CVE-2018-18871

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
20/12/2018
Last modified:
24/08/2020

Description

Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without knowing the original password).

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:gigasetpro:maxwell_basic_firmware:2.22.7:*:*:*:*:*:*:*
cpe:2.3:h:gigasetpro:maxwell_basic:-:*:*:*:*:*:*:*