A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the same network as the device) to change the admin password without authentication via a POST request.
References
Link | Resource |
---|---|
https://www.sit.fraunhofer.de/fileadmin/dokumente/CVE/Advisory_AudioCodes_405HD.pdf | Mitigation Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2019-04-25 13:29
Updated : 2019-04-26 12:56
NVD link : CVE-2018-16219
Mitre link : CVE-2018-16219
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
audiocodes
- 405hd
- 405hd_firmware