splicecom records
4 published records for vendor splicecom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-295 Improper Certificate Validation2
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-33759No exploit | SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authenticatiosplicecom · maximiser soft pbx · CWE-307 | Critical9.8 | — | 0.8% | Jan 25, 2024 |
24Monitor | CVE-2023-33758No exploit | Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEsplicecom · maximiser soft pbx · CWE-79 | Medium6.1 | — | 0.4% | Jan 25, 2024 |
23Monitor | CVE-2023-33757No exploit | A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and splicecom · ipcs · CWE-295 | Medium5.9 | — | 0.3% | Jan 25, 2024 |
21Monitor | CVE-2023-33760No exploit | SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate.splicecom · maximiser soft pbx · CWE-295 | Medium5.3 | — | 0.3% | Jan 25, 2024 |
- CVE-2023-3375939Monitor
SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authenticatio
CriticalCVSS 9.8No exploitEPSS 1%splicecom · maximiser soft pbxJan 25, 2024
- CVE-2023-3375824Monitor
Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DE
MediumCVSS 6.1No exploitEPSS 0%splicecom · maximiser soft pbxJan 25, 2024
- CVE-2023-3375723Monitor
A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and
MediumCVSS 5.9No exploitEPSS 0%splicecom · ipcsJan 25, 2024
- CVE-2023-3376021Monitor
SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate.
MediumCVSS 5.3No exploitEPSS 0%splicecom · maximiser soft pbxJan 25, 2024