ZeroHour

CVE-2016-2364

CVSS 3.0
7.5 high
EPSS
2%p82
Published
()
Modified
Description

The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

Vendors
fonality
Products
hud web, fonality
Weakness
CWE-310
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.