CVE-2024-52884

A

n issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.

Configurations

Configuration 1 (hide)

cpe:2.3:a:audiocodes:mediant_session_border_controller:*:*:*:*:*:*:*:*

History

01 May 2025, 14:25

Type Values Removed Values Added
References () https://www.audiocodes.com/solutions-products/products/session-border-controllers-sbcs - () https://www.audiocodes.com/solutions-products/products/session-border-controllers-sbcs - Product
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-078.txt - () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-078.txt - Third Party Advisory
CPE cpe:2.3:a:audiocodes:mediant_session_border_controller:*:*:*:*:*:*:*:*
First Time Audiocodes
Audiocodes mediant Session Border Controller
Summary
  • (es) Se descubrió un problema en AudioCodes Mediant Session Border Controller (SBC) antes de la versión 7.40A.501.841. Debido al uso de una codificación/ofuscación de contraseñas débiles, un atacante con acceso a las exportaciones de configuración (INI) puede descifrar las contraseñas.

10 Feb 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-327

07 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-07 16:15

Updated : 2025-05-01 14:25


NVD link : CVE-2024-52884

Mitre link : CVE-2024-52884

CVE.ORG link : CVE-2024-52884


JSON object : View

CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm