CVE-2024-22064
14.05.2024, 14:56
ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devices connecting over the internet . If the set of keys are leaked or cracked, the user session informations using the keys may be leaked.Enginsight
Vendor | Product | Version |
---|---|---|
zte | zxun-epdg | 𝑥 < 5.20.20 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1051 - Initialization with Hard-Coded Network Resource Configuration DataThe software initializes data using hard-coded values that act as network resource identifiers.
- CWE-665 - Improper InitializationThe software does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.