NA

CVE-2023-29930

Published: 10/05/2023 Updated: 24/05/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote malicious user to execute arbitrary code via the login crednetials to the TFTP server configuration page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

genesys tftp server

Github Repositories

Info and exploit for CVE-2023-29930: blind file read/write in Genesys TFTP provisioning server configuration

TFTPlunder: an exploit for CVE-2023-29930 This is an exploit script for a blind file read / write vulnerability in the Genesys (formerly InIn) TFTP provisioning server Vulnerability info This vulnerability is due to unrestricted configuration options for the TFTP root path and file extensions In other words, from the Admin interface, you can change the TFTP to any directory a