CVE-2024-28065: Medium severity Unify CP IP Phone vulnerability
Published Apr 5, 2024
·Updated
In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.
Affected Software
1 affected component
Unify CP IP Phone
Event History
Apr 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28065?
CVE-2024-28065 is considered a high severity vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2024-28065?
To fix CVE-2024-28065, upgrade to a firmware version that properly encrypts sensitive files.
3
What information is exposed in CVE-2024-28065?
CVE-2024-28065 exposes sensitive information such as the root password hash in unencrypted files.
4
Which software is affected by CVE-2024-28065?
CVE-2024-28065 affects the Unify CP IP Phone firmware version 1.10.4.3.
5
Is there a workaround for CVE-2024-28065?
Currently, the best approach for CVE-2024-28065 is to apply the firmware update as no effective workaround is available.