PT-2023-12759 · Audiocodes · Audiocodes Device Manager Express

Eric Flokstra

·

Published

2023-05-29

·

Updated

2025-01-14

·

CVE-2022-24627

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AudioCodes Device Manager Express versions through 7.8.20002.47752
Description The issue is an unauthenticated SQL injection in the p parameter of the "process login.php" login form. This allows for potential exploitation without the need for authentication.
Recommendations For AudioCodes Device Manager Express versions through 7.8.20002.47752, consider restricting access to the "process login.php" login form until a patch is available. As a temporary workaround, avoid using the p parameter in the login form to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-24627

Affected Products

Audiocodes Device Manager Express