Vulnerabilities > CVE-2024-48353 - Insecure Storage of Sensitive Information vulnerability in Yealink Meeting Server

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
yealink
CWE-922

Summary

Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.

Vulnerable Configurations

Part Description Count
Application
Yealink
1

Common Weakness Enumeration (CWE)