NA

CVE-2024-24681

Published: 23/02/2024 Updated: 28/03/2024

Vulnerability Summary

An issue exists in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version prior to 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.

Exploits

A single, vendorwide, hardcoded AES key in the Yealink Configuration Encrypt Tool used to encrypt provisioning documents was leaked leading to a compromise of confidentiality of provisioning documents ...

Mailing Lists

CloudAware Security Advisory CVE-2024-24681: Insecure AES key in Yealink Configuration Encrypt Tool ======================================================================== Summary ======================================================================== A single, vendorwide, hardcoded AES key in the configuration tool used to encrypt provisionin ...