Lucene search

K
cveMitreCVE-2018-19978
HistoryMay 29, 2019 - 6:29 p.m.

CVE-2018-19978

2019-05-2918:29:00
CWE-119
mitre
web.nvd.nist.gov
86
cve-2018-19978
buffer overflow
auerswald comfort 1200
remote code execution
authenticated attacker
web server vulnerability

CVSS2

7.7

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.002

Percentile

57.7%

A buffer overflow vulnerability in the DHCP and PPPOE configuration interface of the Auerswald COMfort 1200 IP phone 3.4.4.1-10589 allows a remote attacker (authenticated as simple user in the same network as the device) to trigger remote code execution via a POST request (ManufacturerName parameter) to the web server on the device. The web server is running with root privileges and the injected code will also run with root privileges.

Affected configurations

Nvd
Node
auerswaldcomfortel_1200_ip_firmwareMatch3.4.4.1-10589-
AND
auerswaldcomfortel_1200_ipMatch-
VendorProductVersionCPE
auerswaldcomfortel_1200_ip_firmware3.4.4.1-10589cpe:2.3:o:auerswald:comfortel_1200_ip_firmware:3.4.4.1-10589:-:*:*:*:*:*:*
auerswaldcomfortel_1200_ip-cpe:2.3:h:auerswald:comfortel_1200_ip:-:*:*:*:*:*:*:*

CVSS2

7.7

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.002

Percentile

57.7%

Related for CVE-2018-19978