audiocodes CVE Vulnerabilities & Metrics

Focus on audiocodes vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About audiocodes Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with audiocodes. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total audiocodes CVEs: 13
Earliest CVE date: 21 Mar 2019, 16:00 UTC
Latest CVE date: 11 Aug 2023, 20:15 UTC

Latest CVE reference: CVE-2023-22957

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical audiocodes CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.52

Max CVSS: 9.0

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 5
4.0-6.9 5
7.0-8.9 1
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS audiocodes CVEs

These are the five CVEs with the highest CVSS scores for audiocodes, sorted by severity first and recency.

All CVEs for audiocodes

CVE-2023-22957 audiocodes vulnerability CVSS: 0 11 Aug 2023, 20:15 UTC

An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.

CVE-2023-22956 audiocodes vulnerability CVSS: 0 11 Aug 2023, 20:15 UTC

An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.

CVE-2023-22955 audiocodes vulnerability CVSS: 0 11 Aug 2023, 20:15 UTC

An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consists of simple checksum checks for different firmware components. Thus, by knowing how to calculate and where to store the required checksums for the flasher tool, an attacker is able to store malicious firmware.

CVE-2019-9229 audiocodes vulnerability CVSS: 5.8 20 Jul 2019, 00:15 UTC

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can authenticate with the default 1234 password that cannot be changed, and can execute malicious and unauthorized actions.

CVE-2019-9228 audiocodes vulnerability CVSS: 5.0 19 Jul 2019, 23:15 UTC

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management TELNET features allow remote attackers to cause a denial of service (connection slot exhaustion) via 5 unauthenticated connection attempts, because the maximum number of unauthenticated clients that can be configured is 5. NOTE: the vendor's position is that this is a "design choice.

CVE-2019-9231 audiocodes vulnerability CVSS: 6.8 18 Jul 2019, 16:15 UTC

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented.

CVE-2019-9230 audiocodes vulnerability CVSS: 4.3 18 Jul 2019, 15:15 UTC

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.253. A cross-site scripting (XSS) vulnerability in the search function of the management web interface allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

CVE-2018-16220 audiocodes vulnerability CVSS: 4.3 25 Apr 2019, 20:29 UTC

Cross Site Scripting in different input fields (domain field and personal settings) in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an attacker (local or remote) to inject JavaScript into the web interface of the device by manipulating the phone book entries or manipulating the domain name sent to the device from the domain controller.

CVE-2018-16219 audiocodes vulnerability CVSS: 3.3 25 Apr 2019, 20:29 UTC

A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the same network as the device) to change the admin password without authentication via a POST request.

CVE-2018-16216 audiocodes vulnerability CVSS: 7.7 25 Apr 2019, 20:29 UTC

A command injection (missing input validation, escaping) in the monitoring or memory status web interface in AudioCodes 405HD (firmware 2.2.12) VoIP phone allows an authenticated remote attacker in the same network as the device to trigger OS commands (like starting telnetd or opening a reverse shell) via a POST request to the web server. In combination with another attack (unauthenticated password change), the attacker can circumvent the authentication requirement.

CVE-2018-5757 audiocodes vulnerability CVSS: 9.0 01 Apr 2019, 17:29 UTC

An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which uses a parameter in a request to command.cgi from the Monitoring page in the web UI, unsafely puts user-alterable data directly into an OS command, leading to Remote Code Execution via shell metacharacters in the query string.

CVE-2018-10093 audiocodes vulnerability CVSS: 9.0 21 Mar 2019, 16:00 UTC

AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.

CVE-2018-10091 audiocodes vulnerability CVSS: 3.5 21 Mar 2019, 16:00 UTC

AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow XSS.