Impact
The vulnerability exists in the /callrec/sendlogfile endpoint of Eleveo Call Recording Software 9.7.0. An attacker can manipulate requests to this functionality, bypassing the authorization checks that normally protect the endpoint. This improper authorization can allow the attacker to interact with the endpoint in unauthorized ways, as the check is not properly enforced.
Affected Systems
Any deployment of Eleveo Call Recording Software version 9.7.0 that includes the callrec component is affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the vulnerability can be triggered remotely, increasing its potential impact on exposed systems. The EPSS score of < 1% suggests a low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. Nonetheless, the public disclosure of the exploit means that threat actors could attempt to abuse the unauthorized access if the endpoint remains reachable from untrusted networks.
OpenCVE Enrichment