Vulnerability Details CVE-2022-29330
Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.8%
CVSS Severity
CVSS v3 Score 4.9
CVSS v2 Score 4.0
Products affected by CVE-2022-29330
-
cpe:2.3:a:vitalpbx:vitalpbx:-
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.4
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.4-2
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.4-4
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.6-1
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.6-2
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.8
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.9
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.0
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.1
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.2
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.3
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.4
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.5
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.6
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.7