CVE-2023-0350

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
13/03/2023
Last modified:
07/11/2023

Description

Akuvox E11 does not ensure that a file extension is associated with the file provided. This could allow an attacker to upload a file to the device by changing the extension of a malicious file to an accepted file type.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:akuvox:e11_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:akuvox:e11:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools