Skip to content
Noroxi

Fonality records

3 published records for vendor fonality.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    3 records
    • Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 has a hardcoded password for the FTP account, which allows remote att

      CriticalCVSS 9.8No exploitEPSS 2%

      fonality · fonalityJun 19, 2016

    • CVE-2016-2364
      31Monitor

      The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key acro

      HighCVSS 7.5No exploitEPSS 2%

      fonality · hud webJun 19, 2016

    • CVE-2016-2363
      31Monitor

      Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun script, which allows

      HighCVSS 7.8No exploitEPSS 1%

      fonality · fonalityJun 19, 2016