The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attackers to obtain access via an HTTP session on port 10000, as demonstrated by reading the modem password (which is 1234), or reconfiguring "party mode" or "vacation mode."
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-03-01T06:00:00

Updated: 2024-08-04T21:54:44.032Z

Reserved: 2019-03-01T00:00:00

Link: CVE-2019-9484

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-03-01T07:29:00.217

Modified: 2024-11-21T04:51:42.533

Link: CVE-2019-9484

cve-icon Redhat

No data.