7.5
CVSSv3

CVE-2023-22957

Published: 11/08/2023 Updated: 22/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in libac_des3.so on AudioCodes VoIP desk phones up to and including 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.

Vulnerable Product Search on Vulmon Subscribe to Product

audiocodes c470hd_firmware

audiocodes c455hd_firmware

audiocodes c435hd_firmware

audiocodes 445hd_firmware

audiocodes 405hd_firmware

audiocodes c450hd_firmware

Exploits

The AudioCodes VoIP phones store sensitive information, eg credentials and passwords, in encrypted form in their configuration files These encrypted values can also be automatically configured, eg via the "One Voice Operation Center" or other central device management solutions Due to the use of a hardcoded cryptographic key, an attacker with ...