CVE-2019-19942

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
16/03/2020
Last modified:
04/03/2021

Description

Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.18, and Centro Business 2.0 before 8.02.04 allows a remote attacker to perform DNS spoofing against the web interface via crafted hostnames in DHCP requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:swisscom:centro_grande_firmware:*:*:*:*:*:*:*:* 6.14.06 (excluding)
cpe:2.3:h:swisscom:centro_grande:-:*:*:*:*:*:*:*
cpe:2.3:a:swisscom:centro_business:*:*:*:*:*:*:*:* 1.0 (including) 7.10.18 (excluding)
cpe:2.3:a:swisscom:centro_business:*:*:*:*:*:*:*:* 2.0 (including) 8.02.04 (excluding)