Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfq7-h592-v3xj

Опубликовано: 24 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Insecure AES key in Yealink Configuration Encrypt Tool below verrsion 1.2. A single, vendorwide, hardcoded AES key in the configuration tool used to encrypt provisioning documents was leaked leading to a compromise of confidentiality of provisioning documents.

Insecure AES key in Yealink Configuration Encrypt Tool below verrsion 1.2. A single, vendorwide, hardcoded AES key in the configuration tool used to encrypt provisioning documents was leaked leading to a compromise of confidentiality of provisioning documents.

EPSS

Процентиль: 37%
0.00156
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.8
nvd
почти 2 года назад

An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.

EPSS

Процентиль: 37%
0.00156
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798