CVE-2024-52881

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:audiocodes:one_voice_operations_center:*:*:*:*:*:*:*:*

History

01 May 2025, 14:25

Type Values Removed Values Added
References () https://www.audiocodes.com/solutions-products/products/management-products-solutions/one-voice-operations-center - () https://www.audiocodes.com/solutions-products/products/management-products-solutions/one-voice-operations-center - Product
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-079.txt - () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-079.txt - Third Party Advisory
Summary
  • (es) Se descubrió un problema en AudioCodes One Voice Operations Center (OVOC) anterior a la versión 8.4.582. Gracias al uso de una clave codificada, un atacante puede descifrar datos confidenciales, como contraseñas extraídas del archivo de topología.
First Time Audiocodes one Voice Operations Center
Audiocodes
CPE cpe:2.3:a:audiocodes:one_voice_operations_center:*:*:*:*:*:*:*:*

10 Feb 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-321

07 Feb 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-07 16:15

Updated : 2025-05-01 14:25


NVD link : CVE-2024-52881

Mitre link : CVE-2024-52881

CVE.ORG link : CVE-2024-52881


JSON object : View

Products Affected

audiocodes

  • one_voice_operations_center
CWE
CWE-321

Use of Hard-coded Cryptographic Key