CVE-2024-36439

CRITICAL

Swissphone DiCal-RED 4009 - Info Disclosure

Title source: llm
STIX 2.1

Description

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the actual device password.

Scores

CVSS v3 9.4
EPSS 0.0088
EPSS Percentile 54.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Published Aug 22, 2024
Tracked Since Feb 18, 2026