• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CXO50 Oman
    • CXO50
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect 2025
    • Channel Awards 2024
    • All events
  • GITEX
  • Digital Magazine
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

Positive Technologies helps to fix dangerous vulnerability in popular videoconferencing service Yealink

by CXO Staff
January 30, 2024
in News

In mid-January, Positive Technologies' security expert center estimated the number of vulnerable systems allowing an authenticated attacker to infiltrate the LAN at 131.

Positive Technologies helps to fix dangerous vulnerability in popular videoconferencing service Yealink

Yealink has thanked Positive Technologies for discovering the critical vulnerability BDU:2024-00482 in its Yealink Meeting Server videoconferencing system. Yealink is a prominent VoIP provider and is among five major online conferencing vendors. Its products are used in 140 countries. The vendor was notified of the threat per the responsible disclosure policy and released a software patch.

PT SWARM experts found that an adversary who compromised Yealink Meeting Server at the external perimeter could develop the attack on the LAN if the latter lacked an adequately set up demilitarised zone. By exploiting the flaw, the malicious actor gained initial access to the corporate segment.

In mid-January, Positive Technologies’ security expert center estimated the number of vulnerable systems allowing an authenticated attacker to infiltrate the LAN at 131. The countries with the largest share of installations are China (42%), Russia (26%), Poland (7%), Taiwan (4%), Germany (2%), Brazil (2%), and Indonesia (2%).

The vulnerability is categorised as OS Command Injection (CWE-78) and allows injecting operating system commands. Attackers can leverage this type of flaws to gain access to OS password files, application source code, or completely compromise the web server. In 2023, Positive Technologies experts came across this type of vulnerability while doing security analysis and penetration testing in 5% of cases.

Yealink registered the vulnerability as YVD-2023-1257833. To remediate the flaw, which received a CVSS 3.0 score of 9.9, Yealink Meeting Server has to be updated to version 26.0.0.66.

An attempt to exploit YVD-2023-1257833 can be detected with PT Network Attack Discovery, a network traffic analysis (NTA) system, which already contains the necessary rules.

OS Command Injection vulnerabilities can be reliably detected and blocked by web application firewalls, such as PT Application Firewall, or its cloud-based version, PT Cloud Application Firewall. MaxPatrol VM is another tool that detects infrastructure flaws. To lower the risks, we recommend using EDR security tools, such as MaxPatrol EDR. This solution helps to detect malicious activity, alerts the SIEM system, and prevents the adversary from carrying on the attack.

Earlier, in 2021, Positive Technologies experts found vulnerabilities in Zoom: malicious actors could intercept any data from private videoconferences and attack corporate subscribers’ infrastructures.

Tags: featured2Positive TechnologiesYealink
ShareTweet

Related Posts

Orange Maroc modernises its network with Ericsson
Business

Orange Maroc modernises its network with Ericsson

Orange Maroc has taken a major step forward in strengthening its network infrastructure by signing a strategic agreement with Ericsson...

June 9, 2025
Al Fanar Gas Group and Siemens Energy join forces
Business

Al Fanar Gas Group and Siemens Energy join forces

Al Fanar Gas Group, the energy arm of EHC Investment, has signed a strategic Memorandum of Understanding (MoU) with Siemens...

June 9, 2025

Discussion about this post

Latest Issue

Why private cloud matters

Why private cloud matters

June 9, 2025
Orange Maroc modernises its network with Ericsson

Orange Maroc modernises its network with Ericsson

June 9, 2025
Al Fanar Gas Group and Siemens Energy join forces

Al Fanar Gas Group and Siemens Energy join forces

June 9, 2025

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Insights Summit 2025
    • Insight Innovation Summit
    • CX50 Oman
    • CXO50
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
    • Cloud Connect
    • Channel Awards 2023
    • All events
  • Videos
  • GITEX GLOBAL
  • Digital Magazine

© 2024 - CXO Insight Middle East. All Rights Reserved.