7.5
CVE-2023-22957
- EPSS 0.31%
- Veröffentlicht 11.08.2023 20:15:14
- Zuletzt bearbeitet 21.11.2024 07:45:43
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Audiocodes ≫ C470hd Firmware Version <= 3.4.4.1000
Audiocodes ≫ C455hd Firmware Version <= 3.4.4.1000
Audiocodes ≫ C435hd Firmware Version <= 3.4.4.1000
Audiocodes ≫ 445hd Firmware Version <= 3.4.4.1000
Audiocodes ≫ 405hd Firmware Version <= 3.4.4.1000
Audiocodes ≫ C450hd Firmware Version <= 3.4.4.1000
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.533 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.