PT-2023-30404 · Vonage · Vonage Box Telephone Adapter Vdv23

CVE-2023-47304

·

Publicado

2023-12-04

·

Atualizado

2023-12-11

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1
Description An issue was discovered that allows local attackers to bypass UART authentication controls and read/write arbitrary values to the memory of the device. This issue affects the Vonage Box Telephone Adapter VDV23, allowing attackers to manipulate the device's memory.
Recommendations For Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, consider restricting access to the UART interface until a patch is available to prevent local attackers from bypassing authentication controls. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-47304

Produtos afetados

Vonage Box Telephone Adapter Vdv23