Vulnerability Description
beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Beronet | Voice Over Internet Protocol Gateways Firmware | >= 2.0.0, < 3.0.16 |
| Beronet | Bf16001E1Box | - |
| Beronet | Bf16001T1Box | - |
| Beronet | Bf4001E1Box | - |
| Beronet | Bf4001T1Box | - |
| Beronet | Bf64002E1Box | - |
| Beronet | Bf64002T1Box | - |
| Beronet | Bfsb1S0 | - |
| Beronet | Bfsb2Hy | - |
| Beronet | Bfsb2S0 | - |
| Beronet | Bfsb2S02Xo | - |
| Beronet | Bfsb4Xo | - |
| Beronet | Bfsb4Xo4Xs | - |
| Beronet | Bfsb4Xs | - |
| Beronet | Bn16Fxsfax B | - |
| Beronet | Bn16Fxsfax C | - |
Related Weaknesses (CWE)
References
- https://beronet.atlassian.net/wiki/spaces/PUB/pages/88768529/Security+IssuesThird Party Advisory
- https://www.heise.de/security/meldung/Angriffe-auf-VoIP-Gateways-von-beroNet-PatThird Party Advisory
- https://beronet.atlassian.net/wiki/spaces/PUB/pages/88768529/Security+IssuesThird Party Advisory
- https://www.heise.de/security/meldung/Angriffe-auf-VoIP-Gateways-von-beroNet-PatThird Party Advisory
FAQ
What is CVE-2017-18923?
CVE-2017-18923 is a vulnerability with a CVSS score of 7.5 (HIGH). beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials.
How severe is CVE-2017-18923?
CVE-2017-18923 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18923?
Check the references section above for vendor advisories and patch information. Affected products include: Beronet Voice Over Internet Protocol Gateways Firmware, Beronet Bf16001E1Box, Beronet Bf16001T1Box, Beronet Bf4001E1Box, Beronet Bf4001T1Box.