Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Splicecom

First CVE: Jan 25, 2024Active for: 2 yearsTotal CVEs: 4

Splicecom's vulnerability profile centers on unified communications and IP-PBX products, including its Maximiser Soft PBX and IPCS systems, which serve as central switching and call-management appliances in enterprise telephony deployments. The durable signal is concentrated in web-interface and credential-handling weaknesses, including improper certificate validation, cross-site scripting, and insufficient rate-limiting on authentication attempts, which are characteristic of remotely manageable communications infrastructure. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Splicecom over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 25, 2024
2 years ago
Most Recent CVE
Jan 25, 2024
911 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-33759CRITICAL
SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack.
Jan 25, 20249.826NONO
CVE-2023-33757MEDIUM
A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before allows attackers to eavesdrop on
Jan 25, 20245.918NONO
CVE-2023-33760MEDIUM
SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-mid
Jan 25, 20245.317NONO
CVE-2023-33758MEDIUM
Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component.
Jan 25, 20246.117NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
75%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (50.0%)
High2 (50.0%)
Unknown0 (0.0%)
User Interaction
None2 (50.0%)
Unknown0 (0.0%)
Required2 (50.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Splicecom.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Splicecom — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Splicecom's Products

View all 1 CNAs →

Top CWEs