HIGH · 8.8

CVE-2019-9229

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address...

Vulnerability Description

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can authenticate with the default 1234 password that cannot be changed, and can execute malicious and unauthorized actions.

CVSS Score

8.8

HIGH

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AudiocodesMedian 500L-Msbr Firmware>= f7.20a, <= f7.20a.251
AudiocodesMedian 500L-Msbr-
AudiocodesMedian 500-Msbr Firmware>= f7.20a, <= f7.20a.251
AudiocodesMedian 500-Msbr-
AudiocodesMedian M800B-Msbr Firmware>= f7.20a, <= f7.20a.251
AudiocodesMedian M800B-Msbr-
AudiocodesMedian 800C-Msbr Firmware>= f7.20a, <= f7.20a.251
AudiocodesMedian 800C-Msbr-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-9229?

CVE-2019-9229 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address...

How severe is CVE-2019-9229?

CVE-2019-9229 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-9229?

Check the references section above for vendor advisories and patch information. Affected products include: Audiocodes Median 500L-Msbr Firmware, Audiocodes Median 500L-Msbr, Audiocodes Median 500-Msbr Firmware, Audiocodes Median 500-Msbr, Audiocodes Median M800B-Msbr Firmware.