Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Audiocodes Subscribe
Filtered by product 420hd Ip Phone Firmware
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10093 1 Audiocodes 2 420hd Ip Phone, 420hd Ip Phone Firmware 2020-08-24 9.0 HIGH 8.8 HIGH
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.
CVE-2018-5757 1 Audiocodes 2 420hd Ip Phone, 420hd Ip Phone Firmware 2019-04-04 9.0 HIGH 8.8 HIGH
An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a parameter in a request to command.cgi from the Monitoring page in the web UI, unsafely puts user-alterable data directly into an OS command, leading to Remote Code Execution via shell metacharacters in the query string.
CVE-2018-10091 1 Audiocodes 2 420hd Ip Phone, 420hd Ip Phone Firmware 2019-03-25 3.5 LOW 4.8 MEDIUM
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow XSS.