5.9
CVSSv3

CVE-2023-33757

Published: 25/01/2024 Updated: 31/01/2024
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before allows malicious users to eavesdrop on communications via a man-in-the-middle attack.

Vulnerable Product Search on Vulmon Subscribe to Product

splicecom ipcs

splicecom ipcs2

splicecom ipcs 1.3.4

Github Repositories

Splicecom Vulnerabilities and Tools

Splicecom Vulnerabilities Background Splicecom are a telephony provider providing on-prem and hosted solutions Their Maximiser Soft PBX product is a software PBX that can interface with their proprietary phones and apps as well as standard SIP endpoints The Maximiser platfornm drives a number of products for example the current S8000 series soft PBX as well as older 5000 seri