Description
The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-3448 | The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation. |
References
| Link | Providers |
|---|---|
| http://www.kb.cert.org/vuls/id/754056 |
|
History
No history.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-05T23:24:49.124Z
Reserved: 2016-02-12T00:00:00.000Z
Link: CVE-2016-2364
No data.
Status : Deferred
Published: 2016-06-20T01:59:05.820
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-2364
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD