Hidden functionality in Akuvox E11 - CVE-2023-0344

 

Hidden functionality in Akuvox E11 - CVE-2023-0344

Published: March 13, 2023


Vulnerability identifier: #VU73261
CSH Severity: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-0344
CWE-ID: CWE-912
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Akuvox E11
Software vendor:
Akuvox

Description

The vulnerability allows a remote attacker to compromise vulnerable system

The vulnerability exists due to the affected software uses a custom version of dropbear SSH server. A remote attacker can use this functionality to gain full access to the application and compromise the affected system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links