CVE Vulnerabilities

CVE-2024-36439

Improper Privilege Management

Published: Aug 22, 2024 | Modified: Aug 23, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device passwords hash value, without knowing the actual device password.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Potential Mitigations

References