A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 6
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Trueconf Trueconf_Server
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*
|
— |
5.3.9.10013
|
|
Trueconf Trueconf_Server
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*
|
— |
5.3.9.10015
|
|
Trueconf Trueconf_Server
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*
|
5.4.0.12689
|
5.4.9.10072
|
|
Trueconf Trueconf_Server
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*
|
5.4.0.12700
|
5.4.9.10019
|
|
Trueconf Trueconf_Server
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*
|
5.5.0.13826
|
5.5.5.10010
|
|
Trueconf Trueconf_Server
cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*
|
5.5.0.13828
|
5.5.5.10009
|