Vulnerabilities (CVE)

Filtered by vendor Splicecom Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-33760 1 Splicecom 1 Maximiser Soft Pbx 2024-01-31 N/A 5.3 MEDIUM
SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack.
CVE-2023-33759 1 Splicecom 1 Maximiser Soft Pbx 2024-01-31 N/A 9.8 CRITICAL
SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack.
CVE-2023-33758 1 Splicecom 1 Maximiser Soft Pbx 2024-01-31 N/A 6.1 MEDIUM
Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component.
CVE-2023-33757 1 Splicecom 2 Ipcs, Ipcs2 2024-01-31 N/A 5.9 MEDIUM
A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before allows attackers to eavesdrop on communications via a man-in-the-middle attack.