CVE-2016-2364 (fonality, hud_web)

CVE-2016-2364 (fonality, hud_web)

The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers’ installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

Source: CVE-2016-2364 (fonality, hud_web)

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다