Description
An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-27058 | An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password. |
References
History
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Audiocodes Ltd
Audiocodes Ltd voip Phones |
|
| CPEs | cpe:2.3:h:audiocodes_ltd:voip_phones:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Audiocodes Ltd
Audiocodes Ltd voip Phones |
|
| Metrics |
ssvc
|
Subscriptions
Audiocodes
Subscribe
405hd
Subscribe
405hd Firmware
Subscribe
445hd
Subscribe
445hd Firmware
Subscribe
C435hd
Subscribe
C435hd Firmware
Subscribe
C450hd
Subscribe
C450hd Firmware
Subscribe
C455hd
Subscribe
C455hd Firmware
Subscribe
C470hd
Subscribe
C470hd Firmware
Subscribe
Audiocodes Ltd
Subscribe
Voip Phones
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-10T15:48:38.248Z
Reserved: 2023-01-11T00:00:00.000Z
Link: CVE-2023-22957
Updated: 2024-08-02T10:20:31.404Z
Status : Modified
Published: 2023-08-11T20:15:14.787
Modified: 2024-11-21T07:45:43.357
Link: CVE-2023-22957
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD