Vulnerabilities > Swisscom > Centro Grande Firmware > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-03-16 | CVE-2019-19942 | Improper Input Validation vulnerability in Swisscom Centro Business and Centro Grande Firmware Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.18, and Centro Business 2.0 before 8.02.04 allows a remote attacker to perform DNS spoofing against the web interface via crafted hostnames in DHCP requests. | 7.5 |
2020-03-16 | CVE-2019-19940 | OS Command Injection vulnerability in Swisscom Centro Grande Firmware 6.12.02/6.14.00 Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allows remote authenticated users to execute arbitrary commands via command injection. | 7.2 |