CVE-2023-30024 affects MagicJack A921 USB Phone Jack devices with firmware versions prior to V1.4, stemming from a hidden NAND flash memory partition allowing unauthorized read/write access. This vulnerability, rated Medium (CVSS 6.6), enables an attacker with physical access to replace the device's original software with malicious code, potentially leading to ransomware deployment on the connected host computer. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4CPE matchmatch criteria | cpe:2.3:o:magicjack:a921_firmware:1.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.