CVE-2024-24681
Last modified
CVE-2024-24681 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.. EPSS estimates a 1.03% chance of exploitation in the next 30 days.
Description
An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded key (used to encrypt provisioning documents) across customers' installations.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Yealink | Configuration Encryption Tool | < 1.2 |
| Yealink | Configuration Encryption Tool | All versions |
References
- https://github.com/gitaware/CVE/tree/main/CVE-2024-24681Third Party Advisory
- https://seclists.org/fulldisclosure/2024/Feb/22Mailing List
- https://github.com/gitaware/CVE/tree/main/CVE-2024-24681Third Party Advisory
- https://seclists.org/fulldisclosure/2024/Feb/22Mailing List
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-24681?
How severe is CVE-2024-24681?
How do I fix CVE-2024-24681?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-2464This issue occurs during password recovery, where a differen…6.3
- CVE-2024-2465Open redirection vulnerability in CDeX application allows to…7.1
- CVE-2024-2466libcurl did not check the server certificate of TLS connecti…6.5
- CVE-2024-2467A timing-based side-channel flaw exists in the perl-Crypt-Op…5.9
- CVE-2024-2468The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embe…5.4
- CVE-2024-24680An issue was discovered in Django 3.2 before 3.2.24, 4.2 bef…7.5
- CVE-2024-24683Improper Input Validation vulnerability in Apache Hop Engine…6.5
- CVE-2024-24684Multiple stack-based buffer overflow vulnerabilities exist i…7.8
- CVE-2024-24685Multiple stack-based buffer overflow vulnerabilities exist i…7.8
- CVE-2024-24686Multiple stack-based buffer overflow vulnerabilities exist i…7.8
- CVE-2024-2469An attacker with an Administrator role in GitHub Enterprise …7.2
- CVE-2024-24690Improper input validation in some Zoom clients may allow an …6.5
Are you affected by CVE-2024-24681?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
