CVE-2019-3916

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
11/04/2019
Last modified:
24/08/2020

Description

Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker to retrieve the value of the password salt by simply requesting an API URL in a web browser (e.g. /api).

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:verizon:fios_quantum_gateway_g1100_firmware:02.01.00.05:*:*:*:*:*:*:*
cpe:2.3:h:verizon:fios_quantum_gateway_g1100:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools