An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consists of simple checksum checks for different firmware components. Thus, by knowing how to calculate and where to store the required checksums for the flasher tool, an attacker is able to store malicious firmware.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2023-27056 | An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consists of simple checksum checks for different firmware components. Thus, by knowing how to calculate and where to store the required checksums for the flasher tool, an attacker is able to store malicious firmware. | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Thu, 17 Apr 2025 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:h:audiocodes:c455hd:-:*:*:*:*:*:*:* cpe:2.3:h:audiocodes:c470hd:-:*:*:*:*:*:*:* cpe:2.3:o:audiocodes:c435hd_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:audiocodes:c455hd_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:audiocodes:c470hd_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products | Audiocodes c435hd Audiocodes c435hd Firmware Audiocodes c455hd Audiocodes c455hd Firmware Audiocodes c470hd Audiocodes c470hd Firmware | 
Thu, 10 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Audiocodes Ltd Audiocodes Ltd voip Phones | |
| CPEs | cpe:2.3:h:audiocodes_ltd:voip_phones:*:*:*:*:*:*:*:* | |
| Vendors & Products | Audiocodes Ltd Audiocodes Ltd voip Phones | |
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-10T14:32:58.889Z
Reserved: 2023-01-11T00:00:00
Link: CVE-2023-22955
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-02T10:20:31.435Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2023-08-11T20:15:14.607
Modified: 2025-04-17T13:04:52.510
Link: CVE-2023-22955
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.