CVE-2022-24629
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2022-24629 is a newly identified vulnerability in AudioCodes Device Manager Express versions up to 7.8.20002.47752. This issue allows an attacker to execute arbitrary code remotely by exploiting a directory traversal vulnerability in the file upload functionality of BrowseFiles.php. The vulnerability can be found in the "dir" parameter of the upload process, allowing an attacker to upload a malicious .php file to the WebAdmin/admin/AudioCodes_files/ajax/ directory and subsequently execute it on the affected system. This vulnerability poses a serious threat to the security of AudioCodes Device Manager Express installations, and it is recommended that affected organizations apply the necessary patches to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- AudioCodes