PT-2023-12761 · Audiocodes · Audiocodes Device Manager Express

Eric Flokstra

·

Published

2023-05-29

·

Updated

2025-01-14

·

CVE-2022-24629

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AudioCodes Device Manager Express versions through 7.8.20002.47752
Description An issue allows remote code execution via directory traversal in the dir parameter of the file upload functionality of "BrowseFiles.php". An attacker can upload a .php file to "WebAdmin/admin/AudioCodes files/ajax/".
Recommendations For versions through 7.8.20002.47752, as a temporary workaround, consider restricting access to the file upload functionality of BrowseFiles.php until a patch is available. Avoid using the dir parameter in the affected file upload functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-24629

Affected Products

Audiocodes Device Manager Express