CVE-2019-10655
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.3.219 Beta devices allow unauthenticated remote code execution via shell metacharacters in a /manager?action=getlogcat priority field, in conjunction with a buffer overflow (via the phonecookie cookie) to overwrite a data structure and consequently bypass authentication. This can be exploited remotely or via CSRF because the cookie can be placed in an Accept HTTP header in an XMLHttpRequest call to lighttpd.
Published:Mar 30, 2019
Last Modified:Nov 21, 2024
EPS:Mar 30, 2019
EPSS Score:0.85159
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Grandstream
Product
Gac2500
Grandstream
Gac2500
Vendor
Grandstream
Product
Gac2500 Firmware
Grandstream
Gac2500 Firmware
Vendor
Grandstream
Product
Gvc3202
Grandstream
Gvc3202
Vendor
Grandstream
Product
Gvc3202 Firmware
Grandstream
Gvc3202 Firmware
Vendor
Grandstream
Product
Gxp2200
Grandstream
Gxp2200
Vendor
Grandstream
Product
Gxp2200 Firmware
Grandstream
Gxp2200 Firmware
Vendor
Grandstream
Product
Gxv3240
Grandstream
Gxv3240
Vendor
Grandstream
Product
Gxv3240 Firmware
Grandstream
Gxv3240 Firmware
Vendor
Grandstream
Product
Gxv3275
Grandstream
Gxv3275
Vendor
Grandstream
Product
Gxv3275 Firmware
Grandstream
Gxv3275 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
