CVE-2019-9231
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
18/07/2019
Last modified:
26/07/2019
Description
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:audiocodes:mediant_500l-msbr_firmware:*:*:*:*:*:*:*:* | f7.20a (including) | f7.20a.202.307 (excluding) |
| cpe:2.3:h:audiocodes:mediant_500l-msbr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:audiocodes:mediant_500-mbsr_firmware:*:*:*:*:*:*:*:* | f7.20a (including) | f7.20a.202.307 (excluding) |
| cpe:2.3:h:audiocodes:mediant_500-mbsr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:audiocodes:mediant_m800b-msbr_firmware:*:*:*:*:*:*:*:* | f7.20a (including) | f7.20a.202.307 (excluding) |
| cpe:2.3:h:audiocodes:mediant_m800b-msbr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:audiocodes:mediant_800c-msbr_firmware:*:*:*:*:*:*:*:* | f7.20a (including) | f7.20a.202.307 (excluding) |
| cpe:2.3:h:audiocodes:mediant_800c-msbr:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



