Metrics
Affected Vendors & Products
Solution
The vulnerability have been fixed by the Fermax team in version 2024-09 for the authentication and call forwarding services in MeetMe products.
Workaround
No workaround given by the vendor.
Fri, 28 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 28 Mar 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information. | The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an attacker to gain access to some important assets via configuration files. |
Title | Lack of encryption vulnerability in DuoxMe | Insufficiently Protected Credentials vulnerability in MeetMe products |
Weaknesses | CWE-312 | CWE-522 |
Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 28 Mar 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information. | |
Title | Lack of encryption vulnerability in DuoxMe | |
Weaknesses | CWE-312 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-03-28T14:43:57.603Z
Reserved: 2025-03-28T10:32:50.781Z
Link: CVE-2025-2908

Updated: 2025-03-28T14:43:54.579Z

Status : Awaiting Analysis
Published: 2025-03-28T13:15:41.217
Modified: 2025-03-28T18:11:40.180
Link: CVE-2025-2908

No data.

No data.