CVE-2019-9484

HIGH

Glen Dimplex Deutschland GmbH - Info Disclosure

Title source: llm
STIX 2.1

Description

The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attackers to obtain access via an HTTP session on port 10000, as demonstrated by reading the modem password (which is 1234), or reconfiguring "party mode" or "vacation mode."

Scores

CVSS v3 7.5
EPSS 0.0151
EPSS Percentile 71.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-306
Status published
Products (1)
carel/pcoweb_card_firmware
Published Mar 01, 2019
Tracked Since Feb 18, 2026