MEDIUM · 6.6

CVE-2023-30024

The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access. Attackers can exploit this by replacing the origi...

Vulnerability Description

The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access. Attackers can exploit this by replacing the original software with a malicious version, leading to ransomware deployment on the host computer. Affected devices have firmware versions prior to magicJack A921 USB Phone Jack Rev 3.0 V1.4.

CVSS Score

6.6

MEDIUM

CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
MagicjackA921 Firmware1.4
MagicjackA9213.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-30024?

CVE-2023-30024 is a vulnerability with a CVSS score of 6.6 (MEDIUM). The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access. Attackers can exploit this by replacing the origi...

How severe is CVE-2023-30024?

CVE-2023-30024 has been rated MEDIUM with a CVSS base score of 6.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-30024?

Check the references section above for vendor advisories and patch information. Affected products include: Magicjack A921 Firmware, Magicjack A921.