Vulnerability Details CVE-2023-22956
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.4%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2023-22956
-
cpe:2.3:h:audiocodes:405hd:-
-
cpe:2.3:h:audiocodes:445hd:-
-
cpe:2.3:h:audiocodes:c435hd:-
-
cpe:2.3:h:audiocodes:c450hd:-
-
cpe:2.3:h:audiocodes:c455hd:-
-
cpe:2.3:h:audiocodes:c470hd:-
-
cpe:2.3:o:audiocodes:405hd_firmware:-
-
cpe:2.3:o:audiocodes:405hd_firmware:2.2.12
-
cpe:2.3:o:audiocodes:405hd_firmware:3.4.4.1000
-
cpe:2.3:o:audiocodes:445hd_firmware:-
-
cpe:2.3:o:audiocodes:445hd_firmware:3.4.4.1000
-
cpe:2.3:o:audiocodes:c435hd_firmware:-
-
cpe:2.3:o:audiocodes:c435hd_firmware:3.4.4.1000
-
cpe:2.3:o:audiocodes:c450hd_firmware:-
-
cpe:2.3:o:audiocodes:c450hd_firmware:3.4.4.1000
-
cpe:2.3:o:audiocodes:c455hd_firmware:-
-
cpe:2.3:o:audiocodes:c455hd_firmware:3.4.4.1000
-
cpe:2.3:o:audiocodes:c470hd_firmware:-
-
cpe:2.3:o:audiocodes:c470hd_firmware:3.4.4.1000