CVE-2023-42717
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.4%
exploitation probability
0.4%top 63% of all CVEs
observed exploitation
nono source reports it
In short
A telephony service fails to properly check user permissions, allowing someone to access sensitive information remotely without needing special privileges.
Technical detail
Missing permission validation in a telephony service enables unauthenticated or low-privileged remote attackers to access restricted information disclosure. The vulnerability requires network access to the service but no privilege escalation; the absence of authorization checks allows information leakage.
Summary generated and translated by AI from the official description.
In telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed