PT-2024-12441 · Splicecom · Splicecom Maximiser Soft Pbx

CVE-2023-33760

·

Published

2024-01-25

·

Updated

2024-01-31

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SpliceCom Maximiser Soft PBX versions 1.5 and before
Description The issue allows attackers to eavesdrop on communications via a man-in-the-middle attack because the software utilizes a default SSL certificate.
Recommendations For SpliceCom Maximiser Soft PBX versions 1.5 and before, consider replacing the default SSL certificate with a unique, properly configured certificate to prevent man-in-the-middle attacks.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-33760

Affected Products

Splicecom Maximiser Soft Pbx