PT-2023-14626 · Unknown · Livebox Collaboration Vdesk

·

CVE-2022-45170

·

Publicado

2023-04-14

·

Atualizado

2023-04-19

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LIVEBOX Collaboration vDesk versions through v018
Description A cryptographic issue can occur under the "/api/v1/vencrypt/decrypt/file" endpoint, allowing a malicious user, logged into a victim's account, to decipher a file without knowing the key set by the user.
Recommendations For versions through v018, as a temporary workaround, consider restricting access to the "/api/v1/vencrypt/decrypt/file" endpoint until a patch is available.

Exploit

Correção

Use of a Broken Cryptographic Algorithm

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-45170

Produtos afetados

Livebox Collaboration Vdesk