7.5
CVSSv3

CVE-2016-2364

Published: 20/06/2016 Updated: 21/06/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Chrome HUDweb plugin prior to 2016-05-05 for Fonality (previously trixbox Pro) 12.6 up to and including 14.1i uses the same hardcoded private key across different customers' installations, which allows remote malicious users to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

Vulnerable Product Search on Vulmon Subscribe to Product

fonality hud_web

fonality fonality 12.8

fonality fonality 12.6

fonality fonality 14.1i