10

CVE-2009-1048

The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SnomSnom 300 Firmware Version >= 6.5 < 6.5.20
   SnomSnom 300 Version-
SnomSnom 300 Firmware Version >= 7.1 < 7.1.39
   SnomSnom 300 Version-
SnomSnom 300 Firmware Version >= 7.3 < 7.3.14
   SnomSnom 300 Version-
SnomSnom 320 Firmware Version >= 6.5 < 6.5.20
   SnomSnom 320 Version-
SnomSnom 320 Firmware Version >= 7.1 < 7.1.39
   SnomSnom 320 Version-
SnomSnom 320 Firmware Version >= 7.3 < 7.3.14
   SnomSnom 320 Version-
SnomSnom 360 Firmware Version >= 6.5 < 6.5.20
   SnomSnom 360 Version-
SnomSnom 360 Firmware Version >= 7.1 < 7.1.39
   SnomSnom 360 Version-
SnomSnom 360 Firmware Version >= 7.3 < 7.3.14
   SnomSnom 360 Version-
SnomSnom 370 Firmware Version >= 6.5 < 6.5.20
   SnomSnom 370 Version-
SnomSnom 370 Firmware Version >= 7.1 < 7.1.39
   SnomSnom 370 Version-
SnomSnom 370 Firmware Version >= 7.3 < 7.3.14
   SnomSnom 370 Version-
SnomSnom 820 Firmware Version >= 6.5 < 6.5.20
   SnomSnom 820 Version-
SnomSnom 820 Firmware Version >= 7.1 < 7.1.39
   SnomSnom 820 Version-
SnomSnom 820 Firmware Version >= 7.3 < 7.3.14
   SnomSnom 820 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.26% 0.868
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-290 Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.