Vulnerability Description
Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without knowing the original password).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gigasetpro | Maxwell Basic Firmware | 2.22.7 |
| Gigasetpro | Maxwell Basic | - |
Related Weaknesses (CWE)
References
- https://www.sit.fraunhofer.de/fileadmin/dokumente/CVE/Advisory_Gigaset_Maxwell.pExploitThird Party Advisory
- https://www.sit.fraunhofer.de/fileadmin/dokumente/CVE/Advisory_Gigaset_Maxwell.pExploitThird Party Advisory
FAQ
What is CVE-2018-18871?
CVE-2018-18871 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin passw...
How severe is CVE-2018-18871?
CVE-2018-18871 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-18871?
Check the references section above for vendor advisories and patch information. Affected products include: Gigasetpro Maxwell Basic Firmware, Gigasetpro Maxwell Basic.