Vulnerability Description
AudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise installation with Skype for Business.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Audiocodes | 440Hd Firmware | <= 3.1.2.89 |
| Audiocodes | 440Hd | - |
| Audiocodes | 450Hd Firmware | <= 3.1.2.89 |
| Audiocodes | 450Hd | - |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1041956Third Party AdvisoryVDB Entry
- https://seclists.org/bugtraq/2018/Oct/32ExploitMailing ListThird Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-026.tExploitThird Party Advisory
- http://www.securitytracker.com/id/1041956Third Party AdvisoryVDB Entry
- https://seclists.org/bugtraq/2018/Oct/32ExploitMailing ListThird Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-026.tExploitThird Party Advisory
FAQ
What is CVE-2018-18567?
CVE-2018-18567 is a vulnerability with a CVSS score of 5.9 (MEDIUM). AudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used wit...
How severe is CVE-2018-18567?
CVE-2018-18567 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-18567?
Check the references section above for vendor advisories and patch information. Affected products include: Audiocodes 440Hd Firmware, Audiocodes 440Hd, Audiocodes 450Hd Firmware, Audiocodes 450Hd.