CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command. XMPP users are able to inject arbitrary arguments into a system command, which can be used to read files from, and write files to, the sipXcom server. This can also be leveraged to gain remote command execution.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://seclists.org/fulldisclosure/2023/Mar/5 |
|
History
Thu, 13 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-13T15:49:16.469Z
Reserved: 2023-02-06T00:00:00.000Z
Link: CVE-2023-25356
Updated: 2024-08-02T11:18:36.342Z
Status : Modified
Published: 2023-04-04T13:15:08.713
Modified: 2025-02-13T16:15:38.870
Link: CVE-2023-25356
No data.
OpenCVE Enrichment
No data.
Weaknesses