CVE-2009-1048
The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.37% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-290
- Affected
- snom/snom 300 firmware · snom/snom 320 firmware · snom/snom 360 firmware · snom/snom 370 firmware · snom/snom 820 firmware
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/36293Broken Link, Vendor Advisory
- http://www.csnc.ch/misc/files/advisories/cve-2009-1048.txtBroken Link
- http://www.securityfocus.com/archive/1/505723/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52424Third Party Advisory, VDB Entry
- http://secunia.com/advisories/36293Broken Link, Vendor Advisory
- http://www.csnc.ch/misc/files/advisories/cve-2009-1048.txtBroken Link
- http://www.securityfocus.com/archive/1/505723/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52424Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.