CVE-2022-24629

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published May 29, 2023
Updated: Jan 14, 2025
CWE ID 22

Summary

CVE-2022-24629 is a newly identified vulnerability in AudioCodes Device Manager Express versions up to 7.8.20002.47752. This issue allows an attacker to execute arbitrary code remotely by exploiting a directory traversal vulnerability in the file upload functionality of BrowseFiles.php. The vulnerability can be found in the "dir" parameter of the upload process, allowing an attacker to upload a malicious .php file to the WebAdmin/admin/AudioCodes_files/ajax/ directory and subsequently execute it on the affected system. This vulnerability poses a serious threat to the security of AudioCodes Device Manager Express installations, and it is recommended that affected organizations apply the necessary patches to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share