CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.8. See the original NVD description below for full technical details.
Original NVD Description
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with overly permissive file system permissions. Authenticated local users have modify rights on this directory, while the associated web server process runs as NT AUTHORITY\\SYSTEM. As a result, any local user can create or alter server-side scripts within the webroot and then trigger them via HTTP requests, causing arbitrary code to execute with SYSTEM privileges.
Related CVEs
Other vulnerabilities affecting the same vendor(s)