CVE-2019-3915

MEDIUM

Description

Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an unauthenticated attacker with adjacent network access to intercept and replay login requests to gain access to the administrative web interface.

References

http://www.securityfocus.com/bid/107883

https://www.tenable.com/security/research/tra-2019-17

Details

Source: MITRE

Published: 2019-04-11

Updated: 2019-04-12

Type: CWE-287

Risk Information

CVSS v2.0

Base Score: 5.4

Vector: AV:A/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 5.5

Severity: MEDIUM

CVSS v3.0

Base Score: 7.5

Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.6

Severity: HIGH