CVE-2022-28005
Publicada em · Atualizada em
25Vexday Risk Score
Priorize a correção. Ela exploração observada pelo VulnCheck.
ssvc Attendepss 8.3%
da publicação à arma
Publicada no NVD6 de mai.
VulnCheck+568d
probabilidade de exploração
8.3%top 5% das CVEs
exploração observada
simVulnCheck
An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server (via /Electron/download directory traversal in conjunction with a path component that uses backslash characters), leading to cleartext credential disclosure. Afterwards, the authenticated attacker is able to upload a file that overwrites a 3CX service binary, leading to Remote Code Execution as NT AUTHORITY\SYSTEM on Windows installations. NOTE: this issue exists because of an incomplete fix for CVE-2022-48482.
Produtos afetados
n/a · n/a