Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are received by the device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 24 Aug 2024 08:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:swissphone:dical-red_4009:*:*:*:*:*:*:*:*
Vendors & Products Swissphone
Swissphone dical-red 4009
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Swissphone
Swissphone dical-red 4009
CPEs cpe:2.3:h:swissphone:dical-red_4009:*:*:*:*:*:*:*:*
Vendors & Products Swissphone
Swissphone dical-red 4009
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Aug 2024 01:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:swissphone:dical-red_4009:*:*:*:*:*:*:*:*
Vendors & Products Swissphone
Swissphone dical-red 4009
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 22 Aug 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Swissphone
Swissphone dical-red 4009
Weaknesses CWE-284
CPEs cpe:2.3:h:swissphone:dical-red_4009:*:*:*:*:*:*:*:*
Vendors & Products Swissphone
Swissphone dical-red 4009
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 22 Aug 2024 15:45:00 +0000

Type Values Removed Values Added
Description Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are received by the device.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-23T00:09:12.571Z

Reserved: 2024-05-28T00:00:00

Link: CVE-2024-36441

cve-icon Vulnrichment

Updated: 2024-08-23T00:09:12.571Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-22T16:15:08.433

Modified: 2024-11-21T09:22:11.240

Link: CVE-2024-36441

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.