Description
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-11025 | In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480. |
References
| Link | Providers |
|---|---|
| https://cert.vde.com/en-us/advisories/vde-2019-010 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:39:10.085Z
Reserved: 2020-02-24T00:00:00.000Z
Link: CVE-2019-20481
No data.
Status : Modified
Published: 2020-02-24T15:15:11.613
Modified: 2024-11-21T04:38:35.153
Link: CVE-2019-20481
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD