CVE-2009-1048

CRITICAL

snom 300/320/360/370/820 Firmware 6.5-6.5.20 - Authentication Bypass via Host Header Spoofing

Title source: llm
STIX 2.1

Description

The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.

References (4)

Core 4
Core References
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36293
Broken Link, Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/505723/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/52424

Scores

CVSS v3 9.8
EPSS 0.0637
EPSS Percentile 92.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-290
Status published
Products (5)
snom/snom_300_firmware 6.5 - 6.5.20
snom/snom_320_firmware 6.5 - 6.5.20
snom/snom_360_firmware 6.5 - 6.5.20
snom/snom_370_firmware 6.5 - 6.5.20
snom/snom_820_firmware 6.5 - 6.5.20
Published Aug 14, 2009
Tracked Since Feb 18, 2026