Splicecom's vulnerability profile centers on unified communications and IP-PBX products, including its Maximiser Soft PBX and IPCS systems, which serve as central switching and call-management appliances in enterprise telephony deployments. The durable signal is concentrated in web-interface and credential-handling weaknesses, including improper certificate validation, cross-site scripting, and insufficient rate-limiting on authentication attempts, which are characteristic of remotely manageable communications infrastructure. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Splicecom over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33759CRITICAL SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack. | Jan 25, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-33757MEDIUM A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before allows attackers to eavesdrop on | Jan 25, 2024 | 5.9 | 18 | NO | NO |
CVE-2023-33760MEDIUM SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via a man-in-the-mid | Jan 25, 2024 | 5.3 | 17 | NO | NO |
CVE-2023-33758MEDIUM Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login component. | Jan 25, 2024 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Splicecom.
Media articles that mention a CVE ID that affects a product developed by Splicecom — matched by CVE ID, not by vendor name.