PT-2018-14705 · Gigaset · Gigaset Maxwell Basic

Publicado

2018-12-20

·

Atualizado

2020-08-24

·

CVE-2018-18871

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gigaset Maxwell Basic VoIP phones version 2.22.7
Description The issue concerns a missing password verification in the web interface, allowing a remote attacker in the same network as the device to change the admin password without authentication or knowledge of the original password.
Recommendations For version 2.22.7, consider restricting access to the web interface until a fix is available, and avoid using the device's admin password change functionality over an untrusted network.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18871

Produtos afetados

Gigaset Maxwell Basic