CVE-2023-22955
Summary
| CVE | CVE-2023-22955 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-11 20:15:00 UTC |
| Updated | 2023-08-22 17:09:00 UTC |
| Description | An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consists of simple checksum checks for different firmware components. Thus, by knowing how to calculate and where to store the required checksums for the flasher tool, an attacker is able to store malicious firmware. |
Risk And Classification
Problem Types: CWE-345
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Audiocodes | 405hd | - | All | All | All |
| Operating System | Audiocodes | 405hd Firmware | All | All | All | All |
| Hardware | Audiocodes | 445hd | - | All | All | All |
| Operating System | Audiocodes | 445hd Firmware | All | All | All | All |
| Hardware | Audiocodes | C435hd | - | All | All | All |
| Operating System | Audiocodes | C435hd Firmware | All | All | All | All |
| Hardware | Audiocodes | C450hd | - | All | All | All |
| Operating System | Audiocodes | C450hd Firmware | All | All | All | All |
| Hardware | Audiocodes | C455hd | - | All | All | All |
| Operating System | Audiocodes | C455hd Firmware | All | All | All | All |
| Hardware | Audiocodes | C470hd | - | All | All | All |
| Operating System | Audiocodes | C470hd Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-055.txt | MISC | www.syss.de | |
| Full Disclosure: Missing Immutable Root of Trust in Hardware (CWE-1326) / CVE-2023-22955 | FULLDISC | seclists.org | |
| SySS – The Pentest Experts – Ihr Experte für Penetrationstests | MISC | syss.de | |
| AudioCodes VoIP Phones Insufficient Firmware Validation ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.