CVE-2024-52884
HIGHAudioCodes Mediant Session Border Controller < 7.40a.501.841 - Weak Password Encryption in Configuration Exports
Title source: llmDescription
An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.
References (2)
Core 2
Core References
Third Party Advisory
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-078.txt
Scores
CVSS v3
7.5
EPSS
0.0014
EPSS Percentile
4.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-327
Status
published
Products (1)
audiocodes/mediant_session_border_controller
< 7.40a.501.841
Published
Feb 07, 2025
Tracked Since
Feb 18, 2026