PT-2023-16204 · Akuvox · Akuvox E11

Amir Preminger

+1

·

Published

2023-03-13

·

Updated

2023-03-16

·

CVE-2023-0352

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Akuvox E11 (affected versions not specified)
Description The issue concerns the Akuvox E11 password recovery webpage, which can be accessed without proper authentication. This allows an attacker to download the device key file and subsequently reset the password to its default setting.
Recommendations For Akuvox E11, restrict access to the password recovery webpage until a fix is available. As a temporary workaround, consider disabling the password recovery feature to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2023-0352

Affected Products

Akuvox E11