PT-2025-13515 · Meetme · Meetme

Published

2025-03-28

·

Updated

2025-03-28

·

CVE-2025-2911

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MeetMe products versions prior to 2024-09
Description The issue allows unauthorized access to the call forwarding service system, enabling an attacker to identify multiple users and perform brute force attacks via extensions.
Recommendations For versions prior to 2024-09, update to a version released after 2024-09 to resolve the issue. As a temporary workaround, consider restricting access to the call forwarding service system to minimize the risk of exploitation.

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2911

Affected Products

Meetme