CVE-2019-3916
Last modified
CVE-2019-3916 is a vulnerability of currently unknown severity. Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker to retrieve the value of the password salt by simply requesting an API URL in a web browser (e.g. /api).. EPSS estimates a 2.06% chance of exploitation in the next 30 days.
Description
Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remote, unauthenticated attacker to retrieve the value of the password salt by simply requesting an API URL in a web browser (e.g. /api).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Verizon | Fios Quantum Gateway G1100 Firmware | 02.01.00.05 |
References
- https://www.tenable.com/security/research/tra-2019-17Third Party Advisory
- https://www.tenable.com/security/research/tra-2019-17Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3916?
How severe is CVE-2019-3916?
How do I fix CVE-2019-3916?
Are you affected by CVE-2019-3916?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
