The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2016-06-20T01:00:00

Updated: 2024-08-05T23:24:49.124Z

Reserved: 2016-02-12T00:00:00

Link: CVE-2016-2364

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2016-06-20T01:59:05.820

Modified: 2016-06-21T18:25:22.600

Link: CVE-2016-2364

cve-icon Redhat

No data.