CVE-2022-29330

Severity CVSS v4.0:
Pending analysis
Type:
CWE-330 Use of Insufficiently Random Value
Publication date:
24/06/2022
Last modified:
08/08/2023

Description

Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vitalpbx:vitalpbx:*:*:*:*:*:*:*:* 3.2.1 (excluding)