CVE-2022-24632 is a directory traversal vulnerability affecting AudioCodes Device Manager Express through version 7.8.20002.47752, specifically during file downloads via the BrowseFiles.php view parameter. This medium-severity vulnerability (CVSS 5.3) allows an unauthenticated attacker to access sensitive files on the system, potentially leading to information disclosure. While not actively exploited in the wild and lacking significant community discussion or media coverage, a public exploit for Remote Code Execution (RCE) is available on ExploitDB, indicating a higher potential risk than its CVSS score suggests.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.8.20002.47752CPE matchmatch criteria | cpe:2.3:a:audiocodes:device_manager_express:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.