The Akuvox E11 web server backend library allows command injection in the device phone-book contacts functionality. This could allow an attacker to upload files with executable command instructions.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:54:58.830Z

Reserved: 2023-01-17T19:26:54.871Z

Link: CVE-2023-0351

cve-icon Vulnrichment

Updated: 2024-08-02T05:10:55.649Z

cve-icon NVD

Status : Modified

Published: 2023-03-13T21:15:13.563

Modified: 2024-11-21T07:37:01.660

Link: CVE-2023-0351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.