Vulnerability Details CVE-2022-29330
Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 54.9%
CVSS Severity
CVSS v3 Score 4.9
CVSS v2 Score 4.0
Products affected by CVE-2022-29330
-
cpe:2.3:a:vitalpbx:vitalpbx:-
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.4
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.4-2
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.4-4
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.6-1
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.6-2
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.8
-
cpe:2.3:a:vitalpbx:vitalpbx:3.0.9
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.0
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.1
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.2
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.3
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.4
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.5
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.6
-
cpe:2.3:a:vitalpbx:vitalpbx:3.1.7