CVE-2023-42716
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
In short
A telephony service fails to properly check user permissions, allowing someone to access sensitive information remotely without needing special privileges. This means unauthorized users could read data they shouldn't have access to.
Technical detail
Missing permission validation in a telephony service enables unauthenticated or low-privileged remote attackers to access confidential information through direct service interaction. The vulnerability stems from inadequate access control checks on sensitive operations, resulting in information disclosure without privilege escalation requirements.
Summary generated and translated by AI from the official description.
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N