CVE-2019-20481
CRITICALCVSS 9.8/10EPSS 0.59%
Last modified
CVE-2019-20481 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Miele | Xgw 3000 Zigbee Gateway Firmware | < 2.4.0 |
References
- https://cert.vde.com/en-us/advisories/vde-2019-010Third Party Advisory
- https://cert.vde.com/en-us/advisories/vde-2019-010Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-20481?
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.
How severe is CVE-2019-20481?
CVE-2019-20481 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.59% probability of exploitation in the next 30 days.
How do I fix CVE-2019-20481?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-20473An issue was discovered on TK-Star Q90 Junior GPS horloge 3.…6.8
- CVE-2019-20474An issue was discovered in Zoho ManageEngine Remote Access P…4.3
- CVE-2019-20477PyYAML 5.1 through 5.1.2 has insufficient restrictions on th…9.8
- CVE-2019-20478In ruamel.yaml through 0.16.7, the load method allows remote…9.8
- CVE-2019-20479A flaw was found in mod_auth_openidc before version 2.4.1. A…6.1
- CVE-2019-20480In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious w…8.8
- CVE-2019-20483An issue was discovered in Viki Vera 4.9.1.26180. An attacke…5.4
- CVE-2019-20484An issue was discovered in Viki Vera 4.9.1.26180. A user wit…8.1
- CVE-2019-20485qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the ho…5.7
- CVE-2019-20486An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 device…6.1
- CVE-2019-20487An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 device…8.8
- CVE-2019-20488An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 device…9.8
Are you affected by CVE-2019-20481?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
