CVE-2024-48353: High severity yealink meeting server vulnerability
Published Nov 1, 2024
·Updated
Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.
Affected Software
1 affected component
Yealink Yealink Meeting Server<26.0.0.67
Event History
Nov 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-48353?
CVE-2024-48353 is rated as high severity due to its potential to expose sensitive information.
2
How do I fix CVE-2024-48353?
To fix CVE-2024-48353, upgrade Yealink Meeting Server to version 26.0.0.67 or later.
3
What versions of Yealink Meeting Server are affected by CVE-2024-48353?
Yealink Meeting Server versions prior to 26.0.0.67 are affected by CVE-2024-48353.
4
What can attackers do with CVE-2024-48353?
Attackers can obtain static key information and decrypt plaintext passwords from the front-end JS file due to CVE-2024-48353.
5
Is there a vulnerability disclosure for CVE-2024-48353?
Yes, vulnerabilities like CVE-2024-48353 are typically disclosed through security advisories by the vendor, such as Yealink.