← back
CVE-2023-42717

CVE-2023-42717

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.4%
exploitation probability
0.4%top 63% of all CVEs
observed exploitation
nono source reports it
In short

A telephony service fails to properly check user permissions, allowing someone to access sensitive information remotely without needing special privileges.

Technical detail

Missing permission validation in a telephony service enables unauthenticated or low-privileged remote attackers to access restricted information disclosure. The vulnerability requires network access to the service but no privilege escalation; the absence of authorization checks allows information leakage.

Summary generated and translated by AI from the official description.
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed