Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to connect and compromise the device, potentially pivoting to connected network or hardware devices.
History

Tue, 17 Jun 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Digigram
Digigram pyko-out
Weaknesses CWE-862
CPEs cpe:2.3:a:digigram:pyko-out:-:*:*:*:*:*:*:*
Vendors & Products Digigram
Digigram pyko-out

Mon, 12 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 02 May 2025 16:45:00 +0000

Type Values Removed Values Added
References

Fri, 02 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to connect and compromise the device, potentially pivoting to connected network or hardware devices.
Title CVE-2025-3927
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2025-05-02T14:36:49.042Z

Updated: 2025-05-12T15:54:40.334Z

Reserved: 2025-04-24T19:07:22.728Z

Link: CVE-2025-3927

cve-icon Vulnrichment

Updated: 2025-05-02T16:03:29.704Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-02T15:15:49.017

Modified: 2025-06-17T14:18:20.087

Link: CVE-2025-3927

cve-icon Redhat

No data.