Read Time:16 Second
Posted by Jeroen J.A.W. Hermans via Fulldisclosure on Feb 20
CloudAware Security Advisory
CVE-2024-24681: Insecure AES key in Yealink Configuration Encrypt Tool
========================================================================
Summary
========================================================================
A single, vendorwide, hardcoded AES key in the configuration tool used to
encrypt provisioning documents was leaked leading to a compromise of
confidentiality of provisioning documents….