CVE-2024-52883 Details
Description
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.
A path traversal vulnerability has been identified in AudioCodes One Voice Operations Center (OVOC) versions prior to 8.4.582. This vulnerability allows for the unauthorized reading of sensitive data. The issue arises in the PHP application at the web path '/ipp/admin/AudioCodes_files/ipp_params.php', where the 'name' GET parameter can be manipulated to access files with a '.csv' extension. Exploiting this vulnerability could lead to the exposure of sensitive information, such as encrypted passwords of assigned devices, including Session Border Controllers, which could be decrypted to gain administrative rights on those devices.
Users are advised to update to AudioCodes One Voice Operations Center version 8.4.582.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| audiocodes one voice operations center | < 8.4.582 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2025 | Initial Analysis | [email protected] |
| Feb 10, 2025 | CVE Modified | CISA-ADP |
| Feb 7, 2025 | New CVE Received | [email protected] |