CVE-2017-18923
Summary
| CVE | CVE-2017-18923 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-29 20:15:00 UTC |
| Updated | 2020-08-05 15:44:00 UTC |
| Description | beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials. |
Risk And Classification
Problem Types: CWE-74
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Beronet | Bf16001e1box | - | All | All | All |
| Hardware | Beronet | Bf16001e1box | - | All | All | All |
| Hardware | Beronet | Bf16001t1box | - | All | All | All |
| Hardware | Beronet | Bf16001t1box | - | All | All | All |
| Hardware | Beronet | Bf4001e1box | - | All | All | All |
| Hardware | Beronet | Bf4001e1box | - | All | All | All |
| Hardware | Beronet | Bf4001t1box | - | All | All | All |
| Hardware | Beronet | Bf4001t1box | - | All | All | All |
| Hardware | Beronet | Bf64002e1box | - | All | All | All |
| Hardware | Beronet | Bf64002e1box | - | All | All | All |
| Hardware | Beronet | Bf64002t1box | - | All | All | All |
| Hardware | Beronet | Bf64002t1box | - | All | All | All |
| Hardware | Beronet | Bfsb1s0 | - | All | All | All |
| Hardware | Beronet | Bfsb1s0 | - | All | All | All |
| Hardware | Beronet | Bfsb2hy | - | All | All | All |
| Hardware | Beronet | Bfsb2hy | - | All | All | All |
| Hardware | Beronet | Bfsb2s0 | - | All | All | All |
| Hardware | Beronet | Bfsb2s0 | - | All | All | All |
| Hardware | Beronet | Bfsb2s02xo | - | All | All | All |
| Hardware | Beronet | Bfsb2s02xo | - | All | All | All |
| Hardware | Beronet | Bfsb4xo | - | All | All | All |
| Hardware | Beronet | Bfsb4xo | - | All | All | All |
| Hardware | Beronet | Bfsb4xo4xs | - | All | All | All |
| Hardware | Beronet | Bfsb4xo4xs | - | All | All | All |
| Hardware | Beronet | Bfsb4xs | - | All | All | All |
| Hardware | Beronet | Bfsb4xs | - | All | All | All |
| Hardware | Beronet | Bn16fxsfax B | - | All | All | All |
| Hardware | Beronet | Bn16fxsfax B | - | All | All | All |
| Hardware | Beronet | Bn16fxsfax C | - | All | All | All |
| Hardware | Beronet | Bn16fxsfax C | - | All | All | All |
| Operating System | Beronet | Voice Over Internet Protocol Gateways Firmware | All | All | All | All |
| Operating System | Beronet | Voice Over Internet Protocol Gateways Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Angriffe auf VoIP-Gateways von beroNet, Patch sorgt für Sicherheit | heise Security | MISC | www.heise.de | Third Party Advisory |
| beroNet Teambereich | MISC | beronet.atlassian.net | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.