CVE-2024-52884

An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.
Configurations

Configuration 1 (hide)

cpe:2.3:a:audiocodes:mediant_session_border_controller:*:*:*:*:*:*:*:*

History

01 May 2025, 14:25

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en AudioCodes Mediant Session Border Controller (SBC) antes de la versión 7.40A.501.841. Debido al uso de una codificación/ofuscación de contraseñas débiles, un atacante con acceso a las exportaciones de configuración (INI) puede descifrar las contraseñas.
First Time Audiocodes
Audiocodes mediant Session Border Controller
References () https://www.audiocodes.com/solutions-products/products/session-border-controllers-sbcs - () https://www.audiocodes.com/solutions-products/products/session-border-controllers-sbcs - Product
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-078.txt - () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-078.txt - Third Party Advisory
CPE cpe:2.3:a:audiocodes:mediant_session_border_controller:*:*:*:*:*:*:*:*

10 Feb 2025, 17:15

Type Values Removed Values Added
CWE CWE-327
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

07 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-07 16:15

Updated : 2025-05-01 14:25


NVD link : CVE-2024-52884

Mitre link : CVE-2024-52884

CVE.ORG link : CVE-2024-52884


JSON object : View

Products Affected

audiocodes

  • mediant_session_border_controller
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm