CVE-2024-36439

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the actual device password.
Configurations

No configuration.

History

21 Nov 2024, 09:22

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Aug/32 -
  • () http://seclists.org/fulldisclosure/2024/Aug/39 -
  • () http://seclists.org/fulldisclosure/2024/Aug/40 -

23 Aug 2024, 16:18

Type Values Removed Values Added
Summary
  • (es) Los dispositivos Swissphone DiCal-RED 4009 permiten a un atacante remoto obtener acceso a la interfaz web administrativa a través del valor hash de la contraseña del dispositivo, sin conocer la contraseña real del dispositivo.

22 Aug 2024, 18:35

Type Values Removed Values Added
CWE CWE-269
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.4

22 Aug 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-22 15:15

Updated : 2024-11-21 09:22


NVD link : CVE-2024-36439

Mitre link : CVE-2024-36439

CVE.ORG link : CVE-2024-36439


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management