Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8619 | The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information. |
Solution
The vulnerabilities have been fixed by the Fermax team in version 3.3.1 of the iOS DuoxMe application and in version 2024-09 for the authentication and call forwarding services in MeetMe products.
Workaround
No workaround given by the vendor.
Fri, 28 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Mar 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information. | |
| Title | Lack of encryption vulnerability in DuoxMe | |
| Weaknesses | CWE-312 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-03-28T13:47:34.455Z
Reserved: 2025-03-28T10:32:51.760Z
Link: CVE-2025-2909
Updated: 2025-03-28T13:47:31.372Z
Status : Awaiting Analysis
Published: 2025-03-28T13:15:41.387
Modified: 2025-03-28T18:11:40.180
Link: CVE-2025-2909
No data.
OpenCVE Enrichment
No data.
EUVD