Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fax Server HIGH 8.8
CVE-2025-34334

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in t…

Fix: after 2.6.23
Fix from $1,950 2025-11-19
Fax Server HIGH 8.8
CVE-2025-34335

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability i…

Fix: 2.6.23+
Fix from $1,950 2025-11-19
Fax Server HIGH 7.8
CVE-2025-34332

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back…

Fix: after 2.6.23
Fix from $1,950 2025-11-19
Fax Server HIGH 7.8
CVE-2025-34333

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with…

Fix: after 2.6.23
Fix from $1,950 2025-11-19
Fax Server CRITICAL 9.8
CVE-2025-34328

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that ex…

Fix: after 2.6.23
Fix from $2,300 2025-11-19
Fax Server CRITICAL 9.8
CVE-2025-34329

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at Audio…

Fix: after 2.6.23
Fix from $2,300 2025-11-19
Fax Server HIGH 7.5
CVE-2025-34331

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 contain an unauthenticated file read vulnerability via th…

Fix: after 2.6.23
Fix from $1,950 2025-11-19
Fax Server MEDIUM 5.3
CVE-2025-34330

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that ex…

Fix: after 2.6.23
Fix from $1,600 2025-11-19
Mp 112 Firmware CRITICAL 9.8
CVE-2025-32106

In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execut…

Fix: after 6.60A.369.002
Fix from $2,300 2025-06-03
One Voice Operations Center HIGH 7.5
CVE-2024-52881

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to d…

Fix: 8.4.582+
Fix from $1,950 2025-02-07
One Voice Operations Center HIGH 7.5
CVE-2024-52883

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be…

Fix: 8.4.582+
Fix from $1,950 2025-02-07
Mediant Session Border Controller HIGH 7.5
CVE-2024-52884

An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encry…

Fix: 7.40a.501.841+
Fix from $1,950 2025-02-07
One Voice Operations Center MEDIUM 6.1
CVE-2024-52882

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API,…

Fix: 8.4.582+
Fix from $1,600 2025-02-07
445hd Firmware HIGH 7.8
CVE-2023-22955

An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consists of simple checksum checks …

Fix: after 3.4.4.1000
Fix from $1,950 2023-08-11
C470hd Firmware HIGH 7.5
CVE-2023-22956

An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to d…

Fix: after 3.4.4.1000
Fix from $1,950 2023-08-11
C470hd Firmware HIGH 7.5
CVE-2023-22957

An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attack…

Fix: after 3.4.4.1000
Fix from $1,950 2023-08-11
Device Manager Express CRITICAL 9.8
CVE-2022-24627EPSS 26%

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of th…

Fix: after 7.8.20002.47752
Fix from $2,300 2023-05-29
Device Manager Express CRITICAL 9.8
CVE-2022-24629EPSS 37%

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal i…

Fix: after 7.8.20002.47752
Fix from $2,300 2023-05-29
Device Manager Express HIGH 7.2
CVE-2022-24628

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is authenticated SQL injection in the id parameter of IPPhon…

Fix: after 7.8.20002.47752
Fix from $1,950 2023-05-29
Device Manager Express HIGH 7.2
CVE-2022-24630EPSS 24%

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_comm…

Fix: after 7.8.20002.47752
Fix from $1,950 2023-05-29
Device Manager Express MEDIUM 5.4
CVE-2022-24631EPSS 43%

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenants.php desc parameter.

Fix: after 7.8.20002.47752
Fix from $1,600 2023-05-29
Device Manager Express MEDIUM 5.3
CVE-2022-24632EPSS 27%

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFi…

Fix: after 7.8.20002.47752
Fix from $1,600 2023-05-29
Median 500l Msbr Firmware HIGH 8.8
CVE-2019-9229

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An i…

Mitigation only
Fix from $1,950 2019-07-20
Median 500l Msbr Firmware HIGH 7.5
CVE-2019-9228

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.2…

Mitigation only
Fix from $1,950 2019-07-19
Mediant 500l Msbr Firmware HIGH 8.8
CVE-2019-9231

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cr…

Mitigation only
Fix from $1,950 2019-07-18
Mediant 500l Msbr Firmware MEDIUM 6.1
CVE-2019-9230

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.253. A cr…

Mitigation only
Fix from $1,600 2019-07-18
405hd Firmware HIGH 8.8
CVE-2018-16219

A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the same netwo…

No fix yet
Fix from $1,950 2019-04-25
405hd Firmware HIGH 8.0
CVE-2018-16216

A command injection (missing input validation, escaping) in the monitoring or memory status web interface in AudioCodes 405HD (firmware 2.2.12) VoIP …

No fix yet
Fix from $1,950 2019-04-25
405hd Firmware MEDIUM 6.1
CVE-2018-16220

Cross Site Scripting in different input fields (domain field and personal settings) in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an att…

Mitigation only
Fix from $1,600 2019-04-25
420hd Ip Phone Firmware HIGH 8.8
CVE-2018-5757EPSS 8%

An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a paramet…

No fix yet
Fix from $1,950 2019-04-01