CVE-2018-18871
Severity CVSS v4.0:
Pending analysis
Type:
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
Publication date:
20/12/2018
Last modified:
24/08/2020
Description
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without knowing the original password).
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:gigasetpro:maxwell_basic_firmware:2.22.7:*:*:*:*:*:*:* | ||
cpe:2.3:h:gigasetpro:maxwell_basic:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page