VendorsSplicecommaximiser_soft_pbxall versions
Vulnerabilities

Splicecom Maximiser Soft Pbx

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-33759
SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack.
Published 2024-01-25 · Modified
9.8EPSS 0.008
CVE-2023-33758
Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component.
Published 2024-01-25 · Modified
6.1EPSS 0.004
CVE-2023-33760
SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-middle attack.
Published 2024-01-25 · Modified
5.3EPSS 0.003