PT-2024-13846 · Grandstream · Grandstream Gxp14Xx+1

N0Obit4

·

Published

2024-03-08

·

Updated

2024-08-26

·

CVE-2023-50015

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grandstream GXP14XX version 1.0.8.9 Grandstream GXP16XX version 1.0.7.13
Description An issue was discovered that allows remote attackers to escalate privileges via incorrect access control using an end-user session-identity token.
Recommendations For Grandstream GXP14XX version 1.0.8.9, consider disabling the use of end-user session-identity tokens until a patch is available. For Grandstream GXP16XX version 1.0.7.13, consider disabling the use of end-user session-identity tokens until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2023-50015

Affected Products

Grandstream Gxp14Xx
Grandstream Gxp16Xx