seclists.org
http://seclists.org/fulldisclosure/2023/Feb/12 CVE-2022-24632
MEDIUM
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
Record summary
CVE-2022-24632 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2025 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBDevice Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)ExploitDB exploitby Eric FlokstraNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-24632