cvelist/2023/4xxx/CVE-2023-4467.json
2024-01-09 17:00:37 +00:00

119 lines
4.2 KiB
JSON

{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2023-4467",
"ASSIGNER": "cna@vuldb.com",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "A vulnerability was found in Poly Trio 8800 7.2.6.0019 and classified as critical. Affected by this issue is some unknown functionality of the component Test Automation Mode. The manipulation leads to backdoor. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249260."
},
{
"lang": "deu",
"value": "Eine Schwachstelle wurde in Poly Trio 8800 7.2.6.0019 gefunden. Sie wurde als kritisch eingestuft. Davon betroffen ist unbekannter Code der Komponente Test Automation Mode. Dank der Manipulation mit unbekannten Daten kann eine backdoor-Schwachstelle ausgenutzt werden. Ein Angriff setzt physischen Zugriff auf dem Zielobjekt voraus. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-912 Backdoor",
"cweId": "CWE-912"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Poly",
"product": {
"product_data": [
{
"product_name": "Trio 8800",
"version": {
"version_data": [
{
"version_affected": "=",
"version_value": "7.2.6.0019"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://vuldb.com/?id.249260",
"refsource": "MISC",
"name": "https://vuldb.com/?id.249260"
},
{
"url": "https://vuldb.com/?ctiid.249260",
"refsource": "MISC",
"name": "https://vuldb.com/?ctiid.249260"
},
{
"url": "https://modzero.com/en/advisories/mz-23-01-poly-voip/",
"refsource": "MISC",
"name": "https://modzero.com/en/advisories/mz-23-01-poly-voip/"
},
{
"url": "https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices",
"refsource": "MISC",
"name": "https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices"
},
{
"url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html",
"refsource": "MISC",
"name": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html"
}
]
},
"credits": [
{
"lang": "en",
"value": "Christoph Wolff"
},
{
"lang": "en",
"value": "Pascal Zenker"
}
],
"impact": {
"cvss": [
{
"version": "3.1",
"baseScore": 6.2,
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"baseSeverity": "MEDIUM"
},
{
"version": "3.0",
"baseScore": 6.2,
"vectorString": "CVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"baseSeverity": "MEDIUM"
},
{
"version": "2.0",
"baseScore": 6.5,
"vectorString": "AV:L/AC:L/Au:M/C:C/I:C/A:C"
}
]
}
}