CVE Dictionary Entry: CVE-2024-30939
DATE PUBLISHED: 2024-05-06
DATE UPDATED: 2024-05-06
Please Note:
Yealink takes the security of our customers and our products seriously. This is a living document and may be subject to updates.
Vulnerability Summary
An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control of an account via a flaw in the factory reset procedure.
Vulnerability CVSS
CVSS Severity: MEDIUM
CVSS Score: 6.8
CVSS Vector String: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Product Affected
Product Family and Model | Affected Software Release | Fixed |
MP5X-Teams | 122.15.0.115 | >= 122.15.0.135 |
MP52-Teams | 145.15.0.65 | >= 145.15.0.80 |
VP59-Teams | 91.15.0.118 | >= 91.15.0.133 |
CP965-Teams | 143.15.0.27 | >= 143.15.0.48 |
DeskVision A24 | No related issues | >= 156.15.0.24 |
MeetingBar 65/86 | No related issues | >= 155.15.0.46 |
MeetingBarA10 | No related issues | >= 278.321.0.32 |
MeetingBarA20/A30 | No related issues | >= 133.320.0.35 |
MeetingEye500 | No related issues | >= 280.320.0.15 |
RoomPanel | No related issues | >= 147.520.0.7 |
RoomPanelPlus | No related issues | >= 269.520.0.12 |
Roomcast | No related issues | >= 144.313.0.1 |
Solution
Yealink has released software updates to fixed the CVE-2024-30939 vulnerability in the new version , please update it in time.
The software, release notes, and other documentation for your voice endpoint can be found at: https://support.yealink.com/en/portal/home
Mitigation
Yealink recommends all customers upgrade to the latest version.
Contact
Any customer using an affected system who is concerned about this vulnerability within their deployment should contact Yealink Technical Support by visiting: https://support.yealink.com/en/portal/home for the latest information.
You might also find value in the high-level security guidance and security news located at: https://support.yealink.com/en/portal/home