PT-2023-14626 · Unknown · Livebox Collaboration Vdesk

Luca Borzacchiello

+1

·

Published

2023-04-14

·

Updated

2023-04-19

·

CVE-2022-45170

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LIVEBOX Collaboration vDesk versions through v018
Description A cryptographic issue can occur under the "/api/v1/vencrypt/decrypt/file" endpoint, allowing a malicious user, logged into a victim's account, to decipher a file without knowing the key set by the user.
Recommendations For versions through v018, as a temporary workaround, consider restricting access to the "/api/v1/vencrypt/decrypt/file" endpoint until a patch is available.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2022-45170

Affected Products

Livebox Collaboration Vdesk