TROYANOSYVIRUS
Volver a CVEs

CVE-2023-22955

HIGH
7.8

Descripcion

An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consists of simple checksum checks for different firmware components. Thus, by knowing how to calculate and where to store the required checksums for the flasher tool, an attacker is able to store malicious firmware.

Detalles CVE

Puntuacion CVSS v3.17.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueLOCAL
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado8/11/2023
Ultima modificacion4/17/2025
Fuentenvd
Avistamientos honeypot0

Productos afectados

audiocodes:405hdaudiocodes:405hd_firmwareaudiocodes:445hdaudiocodes:445hd_firmwareaudiocodes:c450hdaudiocodes:c450hd_firmware

Debilidades (CWE)

CWE-345

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.