← Back

CVE-2009-1048

nvd nist
Published: Aug 14, 2009Modified: Apr 23, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.

Affected (15)

5 products
Snom 300 Firmware
Snom 320 Firmware
Snom 360 Firmware
Snom 370 Firmware
Snom 820 Firmware
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Snom
From 6.5 to 6.5.20
From 7.1 to 7.1.39
From 7.3 to 7.3.14
Running on/withPlatform Versions
Snom
Snom 300
All versions
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Snom
From 6.5 to 6.5.20
From 7.1 to 7.1.39
From 7.3 to 7.3.14
Running on/withPlatform Versions
Snom
Snom 320
All versions
Configuration C
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Snom
From 6.5 to 6.5.20
From 7.1 to 7.1.39
From 7.3 to 7.3.14
Running on/withPlatform Versions
Snom
Snom 360
All versions
Configuration D
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Snom
From 6.5 to 6.5.20
From 7.1 to 7.1.39
From 7.3 to 7.3.14
Running on/withPlatform Versions
Snom
Snom 370
All versions
Configuration E
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Snom
From 6.5 to 6.5.20
From 7.1 to 7.1.39
From 7.3 to 7.3.14
Running on/withPlatform Versions
Snom
Snom 820
All versions

References (8)

Source: cve@mitre.org
Broken LinkVendor Advisory
Source: cve@mitre.org
Broken LinkThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.