The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an attacker to gain access to some important assets via configuration files.
Fixes

Solution

The vulnerability have been fixed by the Fermax team in version 2024-09 for the authentication and call forwarding services in MeetMe products.


Workaround

No workaround given by the vendor.

History

Fri, 28 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Description The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information. The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an attacker to gain access to some important assets via configuration files.
Title Lack of encryption vulnerability in DuoxMe Insufficiently Protected Credentials vulnerability in MeetMe products
Weaknesses CWE-312 CWE-522
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Fri, 28 Mar 2025 12:45:00 +0000

Type Values Removed Values Added
Description The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information.
Title Lack of encryption vulnerability in DuoxMe
Weaknesses CWE-312
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-03-28T14:43:57.603Z

Reserved: 2025-03-28T10:32:50.781Z

Link: CVE-2025-2908

cve-icon Vulnrichment

Updated: 2025-03-28T14:43:54.579Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-28T13:15:41.217

Modified: 2025-03-28T18:11:40.180

Link: CVE-2025-2908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.