[YMCS/YDMP Free Trial Program]Yealink would like to offer Free Trial Program of Yealink device management service for our current eligible customers. You can see the details below.
https://www.yealink.com/ydmp-freetrial-2020


Post Reply 
 
Thread Rating:
  • 0 Votes - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
OpenSSL/Heartbleed & OpenVPN/OpenSSL in phones
Author Message
jasonjayr Offline
Junior Member
**

Posts: 1
Joined: Apr 2014
Reputation: 0
Post: #1
OpenSSL/Heartbleed & OpenVPN/OpenSSL in phones
Has Yealink made a statement regarding the OpenSSL/Heartbleed TLS issue? We use OpenVPN on our T26 & T28 phones and I know the version on our PC's needed updating.

If folks haven't heard about it, check out http://heartbleed.com. This was a very serious vulnerability in OpenSSL that was broken for almost 2 years.

Is there a firmware upgrade necessary or in the works?

Thanks
04-15-2014 12:26 AM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Yealink Support Offline
Administrator
*******

Posts: 2,684
Joined: Dec 2012
Reputation: 24
Post: #2
RE: OpenSSL/Heartbleed & OpenVPN/OpenSSL in phones
I think you should upgrade the version of OpenSSL but not Yealink phones.
04-15-2014 09:54 AM
Find all posts by this user    like0    dislike0 Quote this message in a reply
jcvh Offline
Junior Member
**

Posts: 13
Joined: Nov 2013
Reputation: 0
Post: #3
RE: OpenSSL/Heartbleed & OpenVPN/OpenSSL in phones
Is that all?

Guys, are you even taking this seriously enough? Can you elaborate a little?

At least, (imho) you should make an statement regarding what version of OpenSSL, OpenVPN, and whatever https server are you using in the diverse firmwares of your phones, so we can know for sure if can we be affecetd or not.

Given the case, the phones may leak the admin password of the phone, and/or the SIP credentials, anyone of the two serious enough, if you ask me.

In the other hand, i have been checking some terminals with the latest firmware, and the https part seems to be fine, at least.

Regards!
04-16-2014 12:49 AM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Yealink Support Offline
Administrator
*******

Posts: 2,684
Joined: Dec 2012
Reputation: 24
Post: #4
RE: OpenSSL/Heartbleed & OpenVPN/OpenSSL in phones
Hi jcvh,

Thanks to your opinions. I have submitted your request to our product department.
(This post was last modified: 04-16-2014 08:03 PM by Yealink Support.)
04-16-2014 12:18 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Yealink Support Offline
Administrator
*******

Posts: 2,684
Joined: Dec 2012
Reputation: 24
Post: #5
RE: OpenSSL/Heartbleed & OpenVPN/OpenSSL in phones
[Announcement]Yealink Heartbleed Security Advisory
04-18-2014 05:04 PM
Find all posts by this user    like0    dislike0 Quote this message in a reply
Post Reply 


Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  Problem of OpenVPN simonleung 0 283 04-26-2022 02:24 PM
Last Post: simonleung
  V83 and openvpn problem avayax 12 15,388 03-04-2022 12:10 AM
Last Post: rfrantik@rfcinc.com
  Reconfigure a hundred phones? poznaniak 2 1,358 01-26-2022 06:41 PM
Last Post: poznaniak
  Are legacy phones a security risk? Tinov 2 2,817 01-22-2022 07:41 PM
Last Post: Amelie Davis
  Yealink Phones and CVE-2021-44228 DaveNL 0 1,254 12-15-2021 02:41 PM
Last Post: DaveNL
  integrate Salesforce CRM to Yealink phones mehdi.ett 2 7,495 11-08-2021 02:28 PM
Last Post: JessicaWade
  Phones no longer support Let Encrypt johnbeaumont 19 12,434 10-14-2021 05:32 PM
Last Post: yealink@vespino.nl
  List of service providers for YeaLink phones jaseinatl 1 3,317 03-30-2021 05:16 AM
Last Post: guru@ezeetel.com
  FW 85: OpenVPN changes mkeuter 3 4,673 12-08-2020 07:56 PM
Last Post: klindwort
  Audio problems on phones (t23g i t42s) bob_1921 2 4,058 12-02-2020 04:46 AM
Last Post: bob_1921

Forum Jump:


User(s) browsing this thread: 1 Guest(s)

Contact Us   Yealink   Return to Top   Return to Content   Lite (Archive) Mode   RSS Syndication