Hidden functionality in Akuvox E11 - CVE-2023-0344
Published: March 13, 2023
Vulnerability identifier: #VU73261
CSH Severity: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-0344
CWE-ID: CWE-912
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Akuvox E11
Akuvox E11
Software vendor:
Akuvox
Akuvox
Description
The vulnerability allows a remote attacker to compromise vulnerable system
The vulnerability exists due to the affected software uses a custom version of dropbear SSH server. A remote attacker can use this functionality to gain full access to the application and compromise the affected system.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.