CVE-2019-9229

HIGH

AudioCodes Mediant - Auth Bypass

Title source: llm
STIX 2.1

Description

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can authenticate with the default 1234 password that cannot be changed, and can execute malicious and unauthorized actions.

Scores

CVSS v3 8.8
EPSS 0.0061
EPSS Percentile 44.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-798
Status published
Products (4)
audiocodes/median_500-msbr_firmware f7.20a - f7.20a.251
audiocodes/median_500l-msbr_firmware f7.20a - f7.20a.251
audiocodes/median_800c-msbr_firmware f7.20a - f7.20a.251
audiocodes/median_m800b-msbr_firmware f7.20a - f7.20a.251
Published Jul 20, 2019
Tracked Since Feb 18, 2026