9.8
CVE-2018-18871
- EPSS 0.62%
- Veröffentlicht 20.12.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:47
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without knowing the original password).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gigasetpro ≫ Maxwell Basic Firmware Version2.22.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.62% | 0.676 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.