Swissphone
Swissphone Dical-red 4009: vulnerabilidades y CVE
Swissphone Dical-red 4009 tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-36441 | Media (5.4) | 0.35% | — | 22 ago 2024 | Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are received by the device. |
| CVE-2024-36445 | Crítica (9.8) | 0.98% | — | 22 ago 2024 | Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication. |
| CVE-2024-36444 | Alta (8.1) | 0.51% | — | 22 ago 2024 | cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs. |
| CVE-2024-36442 | Alta (8.8) | 0.74% | — | 22 ago 2024 | cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrary files on the device's file system. |
| CVE-2024-36440 | Media (6.8) | 0.29% | — | 22 ago 2024 | An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administrative device password via password-cracking methods, because unsalted MD5 is… |
| CVE-2024-36439 | Crítica (9.4) | 0.88% | — | 22 ago 2024 | Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the actual device password. |
| CVE-2024-36443 | Alta (7.6) | 0.61% | — | 22 ago 2024 | Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP. |