CVE-2019-20481
—CVSS 3.1
9.8 critical
EPSS
<1%p46
Published
()
Modified
Description
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.
- Vendors
- miele
- Products
- xgw 3000 zigbee gateway firmware
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.