CRITICAL · 9.1

CVE-2023-0354

The Akuvox E11 web server can be accessed without any user authentication, and this could allow an attacker to access sensitive information, as well as create and download packet captures with known d...

Vulnerability Description

The Akuvox E11 web server can be accessed without any user authentication, and this could allow an attacker to access sensitive information, as well as create and download packet captures with known default URLs.

CVSS Score

9.1

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
AkuvoxE11 Firmware-
AkuvoxE11-

References

FAQ

What is CVE-2023-0354?

CVE-2023-0354 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The Akuvox E11 web server can be accessed without any user authentication, and this could allow an attacker to access sensitive information, as well as create and download packet captures with known d...

How severe is CVE-2023-0354?

CVE-2023-0354 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2023-0354?

Check the references section above for vendor advisories and patch information. Affected products include: Akuvox E11 Firmware, Akuvox E11.