Vulnerability Description
Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yealink | Yealink Meeting Server | < 26.0.0.67 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-48353?
CVE-2024-48353 is a vulnerability with a CVSS score of 7.5 (HIGH). Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.
How severe is CVE-2024-48353?
CVE-2024-48353 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-48353?
Check the references section above for vendor advisories and patch information. Affected products include: Yealink Yealink Meeting Server.