First published: Sun Sep 11 2022(Updated: )
Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the recorded calls without authenticate to the system. Attacker sends crafted URL to the system: ip:port//V=2;ChannellD=number;Ext=number;Command=startLM;Client=number;Request=number;R=number number - id of the recorded number.
Credit: cna@cyber.gov.il
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Crystal Reports |
Update to the latest version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36780 is classified as a critical vulnerability due to the potential for unauthorized access to sensitive audio recordings.
To fix CVE-2022-36780, it is recommended to apply security updates from Avdor CIS and implement proper authentication mechanisms.
CVE-2022-36780 affects the Avdor CIS Crystal Quality phone call recorder system.
The impact of CVE-2022-36780 allows attackers to listen to recorded calls without authentication, resulting in severe privacy violations.
Mitigation for CVE-2022-36780 includes enhancing access controls and ensuring all communications are secured to prevent unauthorized URL access.