CVE Feed

    Dashboard / CVE / CVE-2023-30024

    CVE-2023-30024

    The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access. Attackers can exploit this by replacing the original software with a malicious version, leading to ransomware deployment on the host computer. Affected devices have firmware versions prior to magicJack A921 USB Phone Jack Rev 3.0 V1.4.

    Published:Apr 28, 2023
    Last Modified:Jan 31, 2025
    EPS:Apr 28, 2023
    EPSS Score:0.00055
    CVSS Score:6.6

    Affected Products

    Vendor
    Magicjack
    Product
    A921
    Vendor
    Magicjack
    Product
    A921 Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High