CVE-2009-1048
Last modified
CVE-2009-1048 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.. EPSS estimates a 6.37% chance of exploitation in the next 30 days.
Description
The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Snom | Snom 300 Firmware | >= 6.5, < 6.5.20 |
| Snom | Snom 300 Firmware | >= 7.1, < 7.1.39 |
| Snom | Snom 300 Firmware | >= 7.3, < 7.3.14 |
| Snom | Snom 320 Firmware | >= 6.5, < 6.5.20 |
| Snom | Snom 320 Firmware | >= 7.1, < 7.1.39 |
| Snom | Snom 320 Firmware | >= 7.3, < 7.3.14 |
| Snom | Snom 360 Firmware | >= 6.5, < 6.5.20 |
| Snom | Snom 360 Firmware | >= 7.1, < 7.1.39 |
| Snom | Snom 360 Firmware | >= 7.3, < 7.3.14 |
| Snom | Snom 370 Firmware | >= 6.5, < 6.5.20 |
| Snom | Snom 370 Firmware | >= 7.1, < 7.1.39 |
| Snom | Snom 370 Firmware | >= 7.3, < 7.3.14 |
| Snom | Snom 820 Firmware | >= 6.5, < 6.5.20 |
| Snom | Snom 820 Firmware | >= 7.1, < 7.1.39 |
| Snom | Snom 820 Firmware | >= 7.3, < 7.3.14 |
References
- http://secunia.com/advisories/36293Broken Link, Vendor Advisory
- http://www.securityfocus.com/archive/1/505723/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52424Third Party Advisory, VDB Entry
- http://secunia.com/advisories/36293Broken Link, Vendor Advisory
- http://www.securityfocus.com/archive/1/505723/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52424Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-1048?
How severe is CVE-2009-1048?
How do I fix CVE-2009-1048?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-1042Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6…
- CVE-2009-1043Unspecified vulnerability in Microsoft Internet Explorer 8 o…
- CVE-2009-1044Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers t…
- CVE-2009-1045requests/status.xml in VLC 0.9.8a allows remote attackers to…
- CVE-2009-1046The console selection feature in the Linux kernel 2.6.28 bef…
- CVE-2009-1047Cross-site scripting (XSS) vulnerability in the Send by e-ma…
- CVE-2009-1049SQL injection vulnerability in articleCall.php in Bloginator…
- CVE-2009-1050Bloginator 1A allows remote attackers to bypass authenticati…
- CVE-2009-1051FubarForum 1.6 and earlier stores sensitive information unde…
- CVE-2009-1052FireAnt 1.3 and earlier stores sensitive information under t…
- CVE-2009-1053chaozzDB 1.2 and earlier stores sensitive information under …
- CVE-2009-1054Unspecified vulnerability in JustSystems Ichitaro 13, 2004 t…
Are you affected by CVE-2009-1048?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
