---
id: CVE-2022-29330
title: >-
  Missing access control in the backup system of Telesoft VitalPBX before 3.2.1
  allows attackers to access the PJSIP and SIP extension credentials,
  cryptographic keys and voicemails files via unspecified vectors.
summary: >-
  Missing access control in the backup system of Telesoft VitalPBX before 3.2.1
  allows attackers to access the PJSIP and SIP extension credentials,
  cryptographic keys and voicemails files via unspecified vectors.
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-330
vendor: vitalpbx
product: vitalpbx
affected:
  - vitalpbx < 3.2.1
patched:
  - vitalpbx 3.2.1
published: '2022-06-24'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-29330'
references:
  - url: 'https://www.arsouyes.org/blog/2022/2022-06-30-VitalPBX-0day'
    label: cve@mitre.org
  - url: 'http://vitalpbx.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.arsouyes.org/blog/2022/2022-06-30-VitalPBX-0day'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.0094
epssPercentile: 0.59452
ingestedAt: '2026-07-06T17:03:24.778Z'
---

## Overview

Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and SIP extension credentials, cryptographic keys and voicemails files via unspecified vectors.

## Affected

- `vitalpbx < 3.2.1`

## Remediation

Upgrade past the affected range:

- `vitalpbx 3.2.1`
