CVE-2024-28065

MEDIUM

Unify CP IP Phone <1.10.4.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.

Scores

CVSS v3 5.9
EPSS 0.0004
EPSS Percentile 13.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Published Apr 05, 2024
Tracked Since Feb 18, 2026