CVE-2023-25356

HIGH

CoreDial sipXcom <=21.04 - Command Injection

Title source: llm
STIX 2.1

Description

CoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command. XMPP users are able to inject arbitrary arguments into a system command, which can be used to read files from, and write files to, the sipXcom server. This can also be leveraged to gain remote command execution.

Scores

CVSS v3 8.8
EPSS 0.1748
EPSS Percentile 95.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-88
Status published
Products (1)
coredial/sipxcom < 21.04
Published Apr 04, 2023
Tracked Since Feb 18, 2026