PT-2023-30404 · Vonage · Vonage Box Telephone Adapter Vdv23

Published

2023-12-04

·

Updated

2023-12-11

·

CVE-2023-47304

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1
Description An issue was discovered that allows local attackers to bypass UART authentication controls and read/write arbitrary values to the memory of the device. This issue affects the Vonage Box Telephone Adapter VDV23, allowing attackers to manipulate the device's memory.
Recommendations For Vonage Box Telephone Adapter VDV23 version VDV21-3.2.11-0.5.1, consider restricting access to the UART interface until a patch is available to prevent local attackers from bypassing authentication controls. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-47304

Affected Products

Vonage Box Telephone Adapter Vdv23