Vulnerability Description
An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control of an account via a flaw in the factory reset procedure.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yealink | Vp59 Firmware | 91.15.0.118 |
Related Weaknesses (CWE)
References
- https://medium.com/%40deepsahu1/yealink-ip-phone-account-take-over-9bf9e7b847c0?ExploitThird Party Advisory
- https://medium.com/%40deepsahu1/yealink-ip-phone-account-take-over-9bf9e7b847c0?ExploitThird Party Advisory
FAQ
What is CVE-2024-30939?
CVE-2024-30939 is a vulnerability with a CVSS score of 6.8 (MEDIUM). An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control of an account via a flaw in the factory reset procedure.
How severe is CVE-2024-30939?
CVE-2024-30939 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-30939?
Check the references section above for vendor advisories and patch information. Affected products include: Yealink Vp59 Firmware.