Sensitive Data Exposure in Yealink Meeting Server
CVE-2024-48352
7.5HIGH
What is CVE-2024-48352?
The vulnerability presents a serious risk as Yealink Meeting Server prior to version 26.0.0.67 can unintentionally expose sensitive information in server responses. This issue arises when an HTTP request is made with an enterprise ID, potentially revealing confidential data to unauthorized users. Such exposure could lead to data breaches and compromise user privacy, emphasizing the need for timely updates and security measures from affected users.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved