CVE-2019-9229
Summary
| CVE | CVE-2019-9229 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-20 00:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can authenticate with the default 1234 password that cannot be changed, and can execute malicious and unauthorized actions. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Audiocodes | Median 500-msbr | - | All | All | All |
| Hardware | Audiocodes | Median 500-msbr | - | All | All | All |
| Operating System | Audiocodes | Median 500-msbr Firmware | All | All | All | All |
| Hardware | Audiocodes | Median 500l-msbr | - | All | All | All |
| Hardware | Audiocodes | Median 500l-msbr | - | All | All | All |
| Operating System | Audiocodes | Median 500l-msbr Firmware | All | All | All | All |
| Hardware | Audiocodes | Median 800c-msbr | - | All | All | All |
| Hardware | Audiocodes | Median 800c-msbr | - | All | All | All |
| Operating System | Audiocodes | Median 800c-msbr Firmware | All | All | All | All |
| Hardware | Audiocodes | Median M800b-msbr | - | All | All | All |
| Hardware | Audiocodes | Median M800b-msbr | - | All | All | All |
| Operating System | Audiocodes | Median M800b-msbr Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cirosec.de/fileadmin/1._Unternehmen/1.4._Unsere_Kompetenzen/Security_Adv... | MISC | www.cirosec.de | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.