The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an attacker to gain access to some important assets via configuration files.
History

Fri, 28 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Description The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information. The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an attacker to gain access to some important assets via configuration files.
Title Lack of encryption vulnerability in DuoxMe Insufficiently Protected Credentials vulnerability in MeetMe products
Weaknesses CWE-312 CWE-522
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Fri, 28 Mar 2025 12:45:00 +0000

Type Values Removed Values Added
Description The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information.
Title Lack of encryption vulnerability in DuoxMe
Weaknesses CWE-312
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-03-28T12:32:06.355Z

Updated: 2025-03-28T14:43:57.603Z

Reserved: 2025-03-28T10:32:50.781Z

Link: CVE-2025-2908

cve-icon Vulnrichment

Updated: 2025-03-28T14:43:54.579Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-28T13:15:41.217

Modified: 2025-03-28T18:11:40.180

Link: CVE-2025-2908

cve-icon Redhat

No data.