Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Cyril Mueller

#18609of 53,632
14.4Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2020-10298
9.0
2020-03-16
Swisscom · Swisscom Centro Grande · CVE-2019-19940
**Name of the Vulnerable Software and Affected Versions** Swisscom Centro Grande versions prior to 6.16.12 **Description** The issue is related to incorrect input sanitation in text-oriented user interfaces, such as telnet and ssh, allowing remote authenticated users to execute arbitrary commands via command injection. **Recommendations** For versions prior to 6.16.12, update to version 6.16.12 or later to resolve the issue.
PT-2020-10299
5.4
2020-03-16
Swisscom · Swisscom Centro Grande · CVE-2019-19941
**Name of the Vulnerable Software and Affected Versions** Swisscom Centro Grande versions prior to 6.16.12 **Description** The issue is related to missing hostname validation, allowing a remote attacker to inject its local IP address as a domain entry in the DNS service of the router via crafted hostnames in DHCP requests, causing XSS. **Recommendations** For versions prior to 6.16.12, update to version 6.16.12 or later to resolve the issue. As a temporary workaround, consider restricting access to the DNS service of the router to minimize the risk of exploitation.