« Volver al listado

CVE-2009-1048

Estado: ModificadaCrítica (9.8)—

The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-1048",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-08-14T15:16:27.377",
  "references": [
    {
      "url": "http://secunia.com/advisories/36293",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.csnc.ch/misc/files/advisories/cve-2009-1048.txt",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/505723/100/0/threaded",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52424",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/36293",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.csnc.ch/misc/files/advisories/cve-2009-1048.txt",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/505723/100/0/threaded",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52424",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-290"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header."
    },
    {
      "lang": "es",
      "value": "El interface Web en los teléfonos Snom VoIP modelos 320, 360, 270 y 820 con el firmware v6.5 anteriores a 6.5.20, 7.1 anteriores a 7.1.39 y 7.3 anteriores a 7.3.14 permite a atacantes remotos saltarse la autenticación, y reconfigurar el teléfono o hacer un uso arbitrario del mismo, a través de (1) http o (2) peticiones https con la dirección IP 127.0.0.1 en la cabecera Host."
    }
  ],
  "lastModified": "2026-06-16T23:06:23.630",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:snom:snom_300_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C47AC90-80C9-4B17-8F55-1B8BFED83064",
              "versionEndExcluding": "6.5.20",
              "versionStartIncluding": "6.5"
            },
            {
              "criteria": "cpe:2.3:o:snom:snom_300_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D4BB1BA-268E-47AE-B0B0-63F793C71794",
              "versionEndExcluding": "7.1.39",
              "versionStartIncluding": "7.1"
            },
            {
              "criteria": "cpe:2.3:o:snom:snom_300_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8430CE2-6C4A-4200-B946-F0531A199139",
              "versionEndExcluding": "7.3.14",
              "versionStartIncluding": "7.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:snom:snom_300:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "53C8CF7D-C185-42A3-AF2D-4088358150A9"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:snom:snom_320_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B8C016A-CFDA-4C22-97A2-E052C7E73C59",
              "versionEndExcluding": "6.5.20",
              "versionStartIncluding": "6.5"
            },
            {
              "criteria": "cpe:2.3:o:snom:snom_320_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0E4FA76-1F69-46D4-8444-F0CE59CD33AA",
              "versionEndExcluding": "7.1.39",
              "versionStartIncluding": "7.1"
            },
            {
              "criteria": "cpe:2.3:o:snom:snom_320_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0A83F90-7F85-4FD2-AC13-72C4B4FA62B0",
              "versionEndExcluding": "7.3.14",
              "versionStartIncluding": "7.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:snom:snom_320:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2B0A870E-6BEA-4F0C-9D96-698220682DD6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:snom:snom_360_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5CA41185-98DB-48BA-8C4A-9F9202DCFFAD",
              "versionEndExcluding": "6.5.20",
              "versionStartIncluding": "6.5"
            },
            {
              "criteria": "cpe:2.3:o:snom:snom_360_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9575B25-7E2C-4E2D-9746-DA56EA97F015",
              "versionEndExcluding": "7.1.39",
              "versionStartIncluding": "7.1"
            },
            {
              "criteria": "cpe:2.3:o:snom:snom_360_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE5E64C2-5D5F-4ACD-9339-069FE7FE8B6A",
              "versionEndExcluding": "7.3.14",
              "versionStartIncluding": "7.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:snom:snom_360:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DBA7DFDB-2A67-4124-81E3-37E3F211568D"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:snom:snom_370_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F62932D-6442-4A86-A13B-815A7ECF88BA",
              "versionEndExcluding": "6.5.20",
              "versionStartIncluding": "6.5"
            },
            {
              "criteria": "cpe:2.3:o:snom:snom_370_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6883042A-CE06-4E23-B77F-CC76AEFBD9B5",
              "versionEndExcluding": "7.1.39",
              "versionStartIncluding": "7.1"
            },
            {
              "criteria": "cpe:2.3:o:snom:snom_370_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E205BBA8-10C9-4ED4-9248-1D0CE023C129",
              "versionEndExcluding": "7.3.14",
              "versionStartIncluding": "7.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:snom:snom_370:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D685F7DA-CE4F-497F-B863-6C6175712125"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:snom:snom_820_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9E7A799-BA1E-4D45-A261-33B234400A7B",
              "versionEndExcluding": "6.5.20",
              "versionStartIncluding": "6.5"
            },
            {
              "criteria": "cpe:2.3:o:snom:snom_820_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99D04CAF-58A1-42C8-B9FD-B9056EA3C5A4",
              "versionEndExcluding": "7.1.39",
              "versionStartIncluding": "7.1"
            },
            {
              "criteria": "cpe:2.3:o:snom:snom_820_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF2D9D65-BA9F-4A56-90F9-A1C7477B1BC9",
              "versionEndExcluding": "7.3.14",
              "versionStartIncluding": "7.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:snom:snom_820:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "66EEF924-599D-4D5E-88B4-65DE12315F19"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}