CVE-2022-29330

Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.
References
Link Resource
https://www.arsouyes.org/blog/2022/2022-06-30-VitalPBX-0day Exploit Third Party Advisory
http://vitalpbx.com Vendor Advisory
Configurations

Configuration 1

cpe:2.3:a:vitalpbx:vitalpbx:*:*:*:*:*:*:*:*

Information

Published : 2022-06-24 04:15

Updated : 2022-07-05 09:01


NVD link : CVE-2022-29330

Mitre link : CVE-2022-29330

Products Affected
No products.
CWE