Skip to main content

Vendor/product archive

audiocodes / device_manager_express CVEs

Beta · best-effort

6 CVEs tagged to audiocodes / device_manager_express2 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2022-24632

Published May 29, 2023

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24631

Published May 29, 2023

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenants.php desc parameter.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24630

Published May 29, 2023

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24629

Published May 29, 2023

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the fil…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24628

Published May 29, 2023

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is authenticated SQL injection in the id parameter of IPPhoneFirmwareEdit.php.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24627

Published May 29, 2023

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1