The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file. An attacker could then use this page to reset the password back to the default.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2023-03-13T20:15:51.389Z
Updated: 2024-08-02T05:10:55.619Z
Reserved: 2023-01-17T19:27:15.123Z
Link: CVE-2023-0352
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-03-13T21:15:13.653
Modified: 2024-11-21T07:37:01.790
Link: CVE-2023-0352
Redhat
No data.