7.5
CVSSv3

CVE-2023-22956

Published: 11/08/2023 Updated: 22/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists on AudioCodes VoIP desk phones up to and including 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.

Vulnerable Product Search on Vulmon Subscribe to Product

audiocodes c470hd_firmware

audiocodes c455hd_firmware

audiocodes c435hd_firmware

audiocodes 445hd_firmware

audiocodes 405hd_firmware

audiocodes c450hd_firmware

Exploits

The AudioCodes VoIP phones can be managed centrally, whereby configuration files are provided and requested by the phones at a central location These configuration files can also be provided in encrypted form This is intended to protect sensitive information within the configuration files from unauthorized access Due to the use of a hardcoded cr ...