CVE-2019-9228: Audiocodes Median 500-Msbr Firmware
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management TELNET features allow remote attackers to cause a denial of service (connection slot exhaustion) via 5 unauthenticated connection attempts, because the maximum number of unauthenticated clients that can be configured is 5. NOTE: the vendor's position is that this is a "design choice.
Affected products
- Audiocodes Median 500-Msbr Firmware: from f7.20a, up to and including f7.20a.252.062
- Audiocodes Median 500l-Msbr Firmware: from f7.20a, up to and including f7.20a.252.062
- Audiocodes Median 800c-Msbr Firmware: from f7.20a, up to and including f7.20a.252.062
- Audiocodes Median m800b-Msbr Firmware: from f7.20a, up to and including f7.20a.252.062
Published 2019-07-19. Last modified 2026-06-17.