Audiocodes
audiocodes
33 CVEs • 45 products
Products (45)
Click to collapseToggle
Products (45)
Click to collapse
CVEs (33)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Audiocodes 2Fax Server Interactive Voice ResponseDec 11, 2025 Nov 19, 2025 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability in the license activation workflow handled by AudioCodes_files/ActivateL...Show more |
1Audiocodes 2Fax Server Interactive Voice ResponseDec 11, 2025 Nov 19, 2025 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in the fax test functionality implemented by AudioCodes_files/TestFax.php....Show more |
1Audiocodes 2Fax Server Interactive Voice ResponseDec 11, 2025 Nov 19, 2025 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with overly permissive file system permissions. Authenticated local users h...Show more |
1Audiocodes 2Fax Server Interactive Voice ResponseDec 11, 2025 Nov 19, 2025 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back-end Windows services using helper batch scripts located under C:\\F2MA...Show more |
1Audiocodes 2Fax Server Interactive Voice ResponseDec 12, 2025 Nov 19, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 contain an unauthenticated file read vulnerability via the download.php script. The endpoint exposes a file download mechanism t...Show more |
1Audiocodes 2Fax Server Interactive Voice ResponseDec 12, 2025 Nov 19, 2025 6.9 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated prompt upload endpoint at AudioCodes_files/uti...Show more |
1Audiocodes 2Fax Server Interactive Voice ResponseDec 12, 2025 Nov 19, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at AudioCodes_files/ajaxBackupUploadFile.php in the F2MAdmin web interface. The...Show more |
1Audiocodes 2Fax Server Interactive Voice ResponseDec 12, 2025 Nov 19, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated script-management endpoint at AudioCodes_files...Show more |
1Audiocodes 3Mp 112 Firmware Mp 114 FirmwareMp 118 FirmwareJun 18, 2025 Jun 3, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code. |
1Audiocodes 1Mediant Session Border Controller May 1, 2025 Feb 7, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able t...Show more |
1Audiocodes 1One Voice Operations Center May 1, 2025 Feb 7, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication. |
1Audiocodes 1One Voice Operations Center May 1, 2025 Feb 7, 2025 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logge...Show more |
1Audiocodes 1One Voice Operations Center May 1, 2025 Feb 7, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology fil...Show more |
1Audiocodes 6405hd Firmware 445hd FirmwareC435hd Firmware+3 moreNov 21, 2024 Aug 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encr...Show more |
1Audiocodes 6405hd Firmware 445hd FirmwareC435hd Firmware+3 moreNov 21, 2024 Aug 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information...Show more |
1Audiocodes 3405hd Firmware 445hd FirmwareC450hd FirmwareApr 17, 2025 Aug 11, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consists of simple checksum checks for different firmware components. Thus, by knowing how to calculate an...Show more |
1Audiocodes 1Device Manager Express Nov 21, 2024 May 29, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter. |
1Audiocodes 1Device Manager Express Nov 21, 2024 May 29, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenants.php desc parameter. |
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed. |
1Audiocodes 1Device Manager Express Jan 14, 2025 May 29, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php...Show more |