CVE-2024-36439
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
22/08/2024
Last modified:
15/04/2026
Description
Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the actual device password.
Impact
Base Score 3.x
9.40
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://www.swissphone.com/en-us/solutions/components/terminals/radio-data-module-dical-red/
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-038.txt
- http://seclists.org/fulldisclosure/2024/Aug/32
- http://seclists.org/fulldisclosure/2024/Aug/39
- http://seclists.org/fulldisclosure/2024/Aug/40



