CVE-2009-1048
The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.
Published:Aug 14, 2009
Last Modified:Apr 23, 2026
EPS:Aug 14, 2009
EPSS Score:0.0326
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Snom
Product
Snom 300
Snom
Snom 300
Vendor
Snom
Product
Snom 300 Firmware
Snom
Snom 300 Firmware
Vendor
Snom
Product
Snom 320
Snom
Snom 320
Vendor
Snom
Product
Snom 320 Firmware
Snom
Snom 320 Firmware
Vendor
Snom
Product
Snom 360
Snom
Snom 360
Vendor
Snom
Product
Snom 360 Firmware
Snom
Snom 360 Firmware
Vendor
Snom
Product
Snom 370
Snom
Snom 370
Vendor
Snom
Product
Snom 370 Firmware
Snom
Snom 370 Firmware
Vendor
Snom
Product
Snom 820
Snom
Snom 820
Vendor
Snom
Product
Snom 820 Firmware
Snom
Snom 820 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
