PT-2023-2277 · Coredial · Sipxcom
Published
2023-03-03
·
Updated
2023-04-11
·
CVE-2023-25355
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CoreDial sipXcom versions up to and including 21.04
Description
The issue is related to insecure permissions, allowing a user with the ability to run commands as the
daemon user on a sipXcom server to overwrite a service file and escalate their privileges to root. This is due to incorrect assignment of privileges. Exploitation of this issue may allow an attacker to elevate their privileges or execute arbitrary commands.Recommendations
For CoreDial sipXcom versions up to and including 21.04, consider restricting access to the
daemon user to minimize the risk of exploitation. As a temporary workaround, consider disabling the ability to overwrite service files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Incorrect Default Permissions
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sipxcom