CVE-2009-1048
CRITICALsnom 300/320/360/370/820 Firmware 6.5-6.5.20 - Authentication Bypass via Host Header Spoofing
Title source: llmDescription
The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.
References (4)
Core 4
Core References
Broken Link x_refsource_misc
http://www.csnc.ch/misc/files/advisories/cve-2009-1048.txt
Broken Link, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/36293
Broken Link, Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/505723/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/52424
Scores
CVSS v3
9.8
EPSS
0.0637
EPSS Percentile
92.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-290
Status
published
Products (5)
snom/snom_300_firmware
6.5 - 6.5.20
snom/snom_320_firmware
6.5 - 6.5.20
snom/snom_360_firmware
6.5 - 6.5.20
snom/snom_370_firmware
6.5 - 6.5.20
snom/snom_820_firmware
6.5 - 6.5.20
Published
Aug 14, 2009
Tracked Since
Feb 18, 2026