The MagicJack device, a VoIP solution for internet phone calls, contains a hidden NAND flash memory partition allowing unauthorized read/write access. Attackers can exploit this by replacing the original software with a malicious version, leading to ransomware deployment on the host computer. Affected devices have firmware versions prior to magicJack A921 USB Phone Jack Rev 3.0 V1.4.
History

Fri, 31 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-04-28T00:00:00.000Z

Updated: 2025-01-31T16:08:38.178Z

Reserved: 2023-04-07T00:00:00.000Z

Link: CVE-2023-30024

cve-icon Vulnrichment

Updated: 2024-08-02T14:21:44.317Z

cve-icon NVD

Status : Modified

Published: 2023-04-28T13:15:13.920

Modified: 2025-01-31T17:15:11.280

Link: CVE-2023-30024

cve-icon Redhat

No data.