Vulnerability Description
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is no CSRF protection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Miele | Xgw 3000 Zigbee Gateway Firmware | < 2.4.0 |
| Miele | Xgw 3000 Zigbee Gateway | - |
Related Weaknesses (CWE)
References
- https://cert.vde.com/en-us/advisories/vde-2019-010Third Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2019-010Third Party Advisory
FAQ
What is CVE-2019-20480?
CVE-2019-20480 is a vulnerability with a CVSS score of 8.8 (HIGH). In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is...
How severe is CVE-2019-20480?
CVE-2019-20480 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-20480?
Check the references section above for vendor advisories and patch information. Affected products include: Miele Xgw 3000 Zigbee Gateway Firmware, Miele Xgw 3000 Zigbee Gateway.