PT-2023-2277 · Coredial · Sipxcom

Published

2023-03-03

·

Updated

2023-04-11

·

CVE-2023-25355

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CoreDial sipXcom versions up to and including 21.04
Description The issue is related to insecure permissions, allowing a user with the ability to run commands as the daemon user on a sipXcom server to overwrite a service file and escalate their privileges to root. This is due to incorrect assignment of privileges. Exploitation of this issue may allow an attacker to elevate their privileges or execute arbitrary commands.
Recommendations For CoreDial sipXcom versions up to and including 21.04, consider restricting access to the daemon user to minimize the risk of exploitation. As a temporary workaround, consider disabling the ability to overwrite service files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Default Permissions

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

BDU:2023-02038
CVE-2023-25355

Affected Products

Sipxcom