Skip to main content

Vendor archive

audiocodes CVEs

Beta · best-effort

33 CVEs tagged to vendor audiocodes5 Critical, 20 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2024-52883

Published Feb 7, 2025

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authenticati…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52882

Published Feb 7, 2025

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malici…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52881

Published Feb 7, 2025

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22957

Published Aug 11, 2023

An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or co…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2023-22956

Published Aug 11, 2023

An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2022-24632

Published May 29, 2023

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24631

Published May 29, 2023

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenants.php desc parameter.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24630

Published May 29, 2023

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24629

Published May 29, 2023

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the fil…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24628

Published May 29, 2023

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is authenticated SQL injection in the id parameter of IPPhoneFirmwareEdit.php.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24627

Published May 29, 2023

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9229

Published Jul 20, 2019

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to t…

CVSS 8.8 · High

CVE-2019-9228

Published Jul 19, 2019

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH…

CVSS 7.5 · High

CVE-2019-9231

Published Jul 18, 2019

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF…

CVSS 8.8 · High
Showing 1-25 of 33 CVEsPage 1 of 2