CVE Database · CVE-2018-18567
CVSS v3.1
N/A
EPSS
1.18%
Published
Oct 24, 2018
Modified
Nov 21, 2024
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
AudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise installation with Skype for Business.
Weaknesses (CWE)
Affected Products (4)
References (6)