CVE-2019-18661

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
02/11/2019
Last modified:
24/08/2020

Description

Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 to 1. An attack does not achieve administrative control of a device; however, the attacker can view all of the web pages of the administration console.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:fastweb:fastgate_firmware:1.0.1b:*:*:*:*:*:*:*
cpe:2.3:h:fastweb:fastgate:-:*:*:*:*:*:*:*