#VU73256 Weak Password Recovery Mechanism for Forgotten Password in Akuvox E11 - CVE-2023-0352 

 

#VU73256 Weak Password Recovery Mechanism for Forgotten Password in Akuvox E11 - CVE-2023-0352

Published: March 13, 2023


Vulnerability identifier: #VU73256
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-0352
CWE-ID: CWE-640
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Akuvox E11
Software vendor:
Akuvox

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to a weak password recovery mechanism for forgotten password. A remote attacker can download the device key file and reset the password back to the default.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links