CVE-2024-52881 Details
Description
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file.
A vulnerability exists in AudioCodes One Voice Operations Center (OVOC) versions prior to 8.4.582) that allows an attacker to decrypt sensitive information, including passwords, from the topology file. This issue arises from the use of a hard-coded cryptographic key, which is static, weak, and easily guessable. The vulnerability was discovered by reverse engineering the OVOC server, where the class responsible for the decryption was identified. The decrypted passwords can include administrative credentials for assigned devices, such as Session Border Controllers.
Users are advised to update to AudioCodes One Voice Operations Center version 8.4.582.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| audiocodes one voice operations center | < 8.4.582 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2025 | Initial Analysis | [email protected] |
| Feb 10, 2025 | CVE Modified | CISA-ADP |
| Feb 7, 2025 | New CVE Received | [email protected] |