CVE Vulnerabilities

CVE-2019-7163

Improper Authentication

Published: Aug 02, 2019 | Modified: Aug 12, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated user to have access to the web interface without knowing the administrators password.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Alcatel_linkzone_firmware Tcl mw40-v-v1.0_mw40_lu_02.00_02 (including) mw40-v-v1.0_mw40_lu_02.00_02 (including)

Potential Mitigations

References