Vulnerability Description
The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Password field to the xml/setter.xml URI.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Upc | Connect Box Eurodocsis Firmware | ch7465lg-ncip-6.12.18.25-2p6-nosh |
| Upc | Connect Box Eurodocsis | 3.0 |
Related Weaknesses (CWE)
References
- https://github.com/filipi86/ConnectBoxDOCSIS-3.0ExploitThird Party Advisory
- https://github.com/filipi86/ConnectBoxDOCSIS-3.0ExploitThird Party Advisory
FAQ
What is CVE-2019-19967?
CVE-2019-19967 is a vulnerability with a CVSS score of 7.5 (HIGH). The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a cleartext password in a POST request on port 80, as demonstrated by the Password...
How severe is CVE-2019-19967?
CVE-2019-19967 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19967?
Check the references section above for vendor advisories and patch information. Affected products include: Upc Connect Box Eurodocsis Firmware, Upc Connect Box Eurodocsis.