2024-12-08 03:06:42 +00:00

114 lines
3.7 KiB
JSON

{
"id": "CVE-2021-45310",
"sourceIdentifier": "cve@mitre.org",
"published": "2022-02-14T21:15:09.213",
"lastModified": "2024-11-21T06:32:04.880",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to an improper access restriction. Users information such as first name, last name, acount id, server uuid, email address, profile image, number, timestamps, etc can be extracted by sending an unauthenticated HTTP GET request to the https://Switchvox-IP/main?cmd=invalid_browser."
},
{
"lang": "es",
"value": "Sangoma Technologies Corporation Switchvox versi\u00f3n 102409, est\u00e1 afectada por una vulnerabilidad de divulgaci\u00f3n de informaci\u00f3n debido a una restricci\u00f3n de acceso inapropiada. La informaci\u00f3n de usuarios, como el nombre, el apellido, el id de la cuenta, el uuid del servidor, la direcci\u00f3n de correo electr\u00f3nico, la imagen del perfil, el n\u00famero, las marcas de tiempo, etc., puede extraerse mediante el env\u00edo de una petici\u00f3n HTTP GET no autenticada a la direcci\u00f3n https://Switchvox-IP/main?cmd=invalid_browser"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"baseScore": 5.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sangoma:switchvox:102409:*:*:*:*:*:*:*",
"matchCriteriaId": "A2BDC5AC-142E-46A0-A7EF-668BB02AB806"
}
]
}
]
}
],
"references": [
{
"url": "https://github.com/IthacaLabs/Sangoma/tree/main/Switchvox_Version%20102409",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Third Party Advisory"
]
},
{
"url": "https://github.com/IthacaLabs/Sangoma/tree/main/Switchvox_Version%20102409",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}