// For flags

CVE-2019-7163

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass that allows an unauthenticated user to have access to the web interface without knowing the administrator's password.

La interfaz web de los dispositivos LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 de Alcatel, es vulnerable a una omisión de autenticación que permite que un usuario no autenticado tener acceso a la interfaz web sin conocer la contraseña del administrador.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-01-29 CVE Reserved
  • 2019-08-02 CVE Published
  • 2023-11-11 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Tcl
Search vendor "Tcl"
Alcatel Linkzone Firmware
Search vendor "Tcl" for product "Alcatel Linkzone Firmware"
mw40-v-v1.0_mw40_lu_02.00_02
Search vendor "Tcl" for product "Alcatel Linkzone Firmware" and version "mw40-v-v1.0_mw40_lu_02.00_02"
-
Affected
in Tcl
Search vendor "Tcl"
Alcatel Linkzone
Search vendor "Tcl" for product "Alcatel Linkzone"
--
Safe