445
VMScore

CVE-2019-9484

Published: 01/03/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote malicious users to obtain access via an HTTP session on port 10000, as demonstrated by reading the modem password (which is 1234), or reconfiguring "party mode" or "vacation mode."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

carel pcoweb_card_firmware -