CVE-2022-29330

Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.
References
Link Resource
https://www.arsouyes.org/blog/2022/2022-06-30-VitalPBX-0day Exploit Third Party Advisory
http://vitalpbx.com Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:vitalpbx:vitalpbx:*:*:*:*:*:*:*:*

Information

Published : 2022-06-24 09:15

Updated : 2022-07-05 14:01


NVD link : CVE-2022-29330

Mitre link : CVE-2022-29330


JSON object : View

CWE
CWE-862

Missing Authorization

Advertisement

dedicated server usa

Products Affected

vitalpbx

  • vitalpbx