ZeroHour

CVE-2019-20481

CVSS 3.1
9.8 critical
EPSS
<1%p46
Published
()
Modified
Description

In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.

Vendors
miele
Products
xgw 3000 zigbee gateway firmware
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.