CVE-2024-24681: Critical severity Yealink Configuration Encryption Tool vulnerability
An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Yealink Configuration Encrypt Tool (RSA version)to a version that resolves this vulnerability.Fixed in 1.2 - Operational
Replace/rotate the hardcoded encryption key used by Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2), since the same single key is shared across customers' installations.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24681?
CVE-2024-24681 is considered a high severity vulnerability due to the presence of a hardcoded encryption key across multiple customer installations.
How do I fix CVE-2024-24681?
To fix CVE-2024-24681, update to the latest version of the Yealink Configuration Encrypt Tool that addresses the hardcoded key issue.
Which versions of Yealink Configuration Encrypt Tool are affected by CVE-2024-24681?
CVE-2024-24681 affects all versions of the Yealink Configuration Encrypt Tool (RSA version prior to 1.2 and all versions of AES version).
What is the impact of CVE-2024-24681 on customer data?
CVE-2024-24681 may lead to unauthorized access to encrypted provisioning documents due to the use of a shared hardcoded key.
Is there a workaround for CVE-2024-24681 while awaiting a patch?
Currently, there is no recommended workaround for CVE-2024-24681; users should prioritize upgrading to a secure version.