CyberSec.Space Logo
Back to CVE Browser

CVE-2019-9972

HIGH
8.8
CVSS Severity Score
EPSS Score0.0140%
EPSS Percentile22.86th
PublishedJun 7, 2022
Last ModifiedNov 21, 2024

Vulnerability Description

PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of "<space><space> followed by <shift><enter>" mishandling.

Affected Platforms (CPE)

πŸ’»
3cx

Phone System Firmware

= 16.0.0.1570
πŸ’»
Debian

Debian Linux

All versions

References & Advisories

Related Vulnerabilities