CVE-2023-0352

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
13/03/2023
Last modified:
07/11/2023

Description

The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file. An attacker could then use this page to reset the password back to the default.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:akuvox:e11_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:akuvox:e11:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools