CVE-2025-34332
中文标题:
(暂无数据)
英文标题:
AudioCodes Fax/IVR Appliance <= 2.6.23 Insecure Service Control Scripts LPE
漏洞描述
中文描述:
(暂无数据)
英文描述:
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back-end Windows services using helper batch scripts located under C:\\F2MAdmin\\F2E\\AudioCodes_files\\utils\\Services. When certain service actions are requested through ajaxPost.php, these scripts are invoked by PHP using system() under the NT AUTHORITY\\SYSTEM account. The batch files in this directory are writable by any authenticated local user due to overly permissive ACLs, allowing them to replace script contents with arbitrary commands. On the next service start/stop operation, the modified script is executed as SYSTEM, enabling elevation of local privileges.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| AudioCodes Limited | AudioCodes Fax/IVR Appliance | - | ≤ 2.6.23 | - |
cpe:2.3:a:audiocodes_limited:audiocodes_fax_ivr_appliance:*:*:*:*:*:*:*:*
|
| audiocodes | fax_server | * | - | - |
cpe:2.3:a:audiocodes:fax_server:*:*:*:*:*:*:*:*
|
| audiocodes | interactive_voice_response | * | - | - |
cpe:2.3:a:audiocodes:interactive_voice_response:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
4.0 (cna)
HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-34332 |
2025-11-21 02:02:44 | 2026-01-12 02:11:32 |
| NVD | nvd_CVE-2025-34332 |
2025-12-12 03:21:45 | 2026-01-12 02:27:39 |
版本与语言
安全公告
变更历史
查看详细变更
- affected_products_count: 1 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']