CVE-2022-48625: High severity yealink config encrypt tool add rsa vulnerability
Published Feb 19, 2024
·Updated
Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an adversary.
Affected Software
2 affected components
Yealink Config Encrypt Tool<1.2
Yealink Configuration Encryption Tool<1.2
Event History
Feb 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 20, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-48625?
CVE-2022-48625 has been classified as a high severity vulnerability due to the risk of decryption by an adversary.
2
How do I fix CVE-2022-48625?
To mitigate CVE-2022-48625, upgrade to Yealink Config Encrypt Tool version 1.2 or later, which eliminates the use of a built-in RSA key pair.
3
What is CVE-2022-48625 about?
CVE-2022-48625 describes a vulnerability in Yealink Config Encrypt Tool that contains a hardcoded RSA key pair, allowing potential decryption by attackers.
4
Who is affected by CVE-2022-48625?
CVE-2022-48625 affects users of the Yealink Config Encrypt Tool versions prior to 1.2.
5
What type of vulnerability is CVE-2022-48625?
CVE-2022-48625 is categorized as a cryptographic vulnerability due to the use of a hardcoded encryption key.