Back

MEDIUM

Lack of encryption vulnerability in DuoxMe

Published Mar 28, 2025

Description

The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information.

Affected products

Remediation

Vendor solution

The vulnerabilities have been fixed by the Fermax team in version 3.3.1 of the iOS DuoxMe application and in version 2024-09 for the authentication and call forwarding services in MeetMe products.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner INCIBE
Published Mar 28, 2025
Updated Mar 28, 2025
Reserved Mar 28, 2025

CISA Vulnrichment

Updated Mar 28, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner INCIBE
Published Mar 28, 2025
Updated Mar 28, 2025

GitHub

No data