CVE-2018-19978
PoC —CVSS 3.0
8.0 high
EPSS
4%p90
Published
()
Modified
Description
A buffer overflow vulnerability in the DHCP and PPPOE configuration interface of the Auerswald COMfort 1200 IP phone 3.4.4.1-10589 allows a remote attacker (authenticated as simple user in the same network as the device) to trigger remote code execution via a POST request (ManufacturerName parameter) to the web server on the device. The web server is running with root privileges and the injected code will also run with root privileges.
- Vendors
- auerswald
- Products
- comfortel 1200 ip firmware
- Weakness
- CWE-119
- Vector
- CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.