Impact
An unauthenticated attacker with access to the TrueConf Server port 4307/TCP can trigger an undocumented function that lets them execute arbitrary scripts. Because the function lacks authentication checks, the attacker can run any commands on the host, potentially gaining full control and compromising confidentiality, integrity, and availability of the server.
Affected Systems
TrueConf Server versions 5.3.x to 5.3.9, 5.4.x to 5.4.9, 5.5.x to 5.5.5, and all earlier releases are affected. The product is deployed by TrueConf under the TrueConf Server banner.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, and the EPSS score is less than 1%, indicating a very low exploitation probability, although the vulnerability is listed in the CISA KEV catalog. The lack of authentication allows remote exploitation from any network host that can reach port 4307, so the risk is high for exposed servers. The attack requires only network connectivity and no special privileges, making it readily exploitable if the server is reachable.
OpenCVE Enrichment