CVE Vulnerabilities

CVE-2024-28065

Cleartext Storage of Sensitive Information

Published: Apr 05, 2024 | Modified: Mar 28, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Potential Mitigations

References