← Back

Miele

miele

4 CVEs • 4 products

Products (4)

Click to collapse
Toggle

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Miele
1Appwash
Nov 21, 2024
Nov 21, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read and partial write access to other users d...Show more
An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read and partial write access to other users data by modifying a small part of a HTTP request sent to the API. Reading or changing the password of another user was not possible, thus no impact to Availability.Show less
1Miele
1Benchmark Programming Tool
Nov 21, 2024
Apr 27, 2022
N/A· v4
7.3 HIGH· v3
6.9 MEDIUM· v2
In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administr...Show more
In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.Show less
1Miele
1Xgw 3000 Zigbee Gateway Firmware
Nov 21, 2024
Feb 24, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.
1Miele
1Xgw 3000 Zigbee Gateway Firmware
Nov 21, 2024
Feb 24, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is no CSRF protection.