PT-2024-12440 · Splicecom · Splicecom Maximiser Soft Pbx

Published

2024-01-25

·

Updated

2024-01-31

·

CVE-2023-33759

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SpliceCom Maximiser Soft PBX versions 1.5 and before
Description The issue allows attackers to bypass authentication via a brute force attack due to the lack of restriction on excessive authentication attempts.
Recommendations For SpliceCom Maximiser Soft PBX versions 1.5 and before, consider implementing rate limiting or IP blocking to restrict excessive authentication attempts as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2023-33759

Affected Products

Splicecom Maximiser Soft Pbx