7.5
CVE-2024-48352
- EPSS 0.27%
- Veröffentlicht 01.11.2024 17:15:17
- Zuletzt bearbeitet 05.11.2024 21:35:31
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Yealink ≫ Yealink Meeting Server Version < 26.0.0.67
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.5 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-922 Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.