Impact
The vulnerability exists in the /callrec/sendlogfile endpoint of Eleveo Call Recording Software 9.7.0, where an attacker can manipulate the request to bypass authorization checks and read or download log files that are normally protected. This flaw permits unauthorized access to logs that may contain sensitive call metadata, thereby compromising confidentiality.
Affected Systems
Any deployment of Eleveo Call Recording Software version 9.7.0 that includes the callrec component is affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the vulnerability can be triggered remotely, increasing its potential impact on exposed systems. The EPSS score of < 1% suggests a low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. Nonetheless, the public disclosure of the exploit means that threat actors could attempt to abuse the unauthorized access if the endpoint remains reachable from untrusted networks.
OpenCVE Enrichment