Vulnerabilities > CVE-2018-10093 - Missing Authorization vulnerability in Audiocodes 420Hd IP Phone Firmware 2.2.12.126

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
audiocodes
CWE-862
critical
exploit available

Summary

AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.

Vulnerable Configurations

Part Description Count
OS
Audiocodes
1
Hardware
Audiocodes
1

Common Weakness Enumeration (CWE)

Exploit-Db

idEDB-ID:46164
last seen2019-01-14
modified2019-01-14
published2019-01-14
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/46164
titleAudioCode 400HD - Command Injection

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/151116/audiocodeip-exec.txt
idPACKETSTORM:151116
last seen2019-01-13
published2019-01-12
reporterA. Baube
sourcehttps://packetstormsecurity.com/files/151116/AudioCode-400HD-Remote-Command-Injection.html
titleAudioCode 400HD Remote Command Injection