Vulnerability Details CVE-2024-48353
Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the obtained key information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.7%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2024-48353
-
cpe:2.3:a:yealink:yealink_meeting_server:-
-
cpe:2.3:a:yealink:yealink_meeting_server:26.0.0.66