{"id": "CVE-2019-13474", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2019-09-16T12:15:10.847", "references": [{"url": "http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProto-DoS-XSS-Missing-Authentication.html", "source": "cve@mitre.org"}, {"url": "http://seclists.org/fulldisclosure/2019/Sep/12", "tags": ["Mailing List", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "http://seclists.org/fulldisclosure/2023/Sep/1", "source": "cve@mitre.org"}, {"url": "https://www.vulnerability-lab.com/get_content.php?id=2183", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "http://packetstormsecurity.com/files/174503/Internet-Radio-auna-IR-160-SE-UIProto-DoS-XSS-Missing-Authentication.html", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://seclists.org/fulldisclosure/2019/Sep/12", "tags": ["Mailing List", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://seclists.org/fulldisclosure/2023/Sep/1", "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.vulnerability-lab.com/get_content.php?id=2183", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-798"}]}], "descriptions": [{"lang": "en", "value": "TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt, and Imperial i600 TN81HH96-g102h-g102 devices have insufficient access control for the /set_dname, /mylogo, /LocalPlay, /irdevice.xml, /Sendkey, /setvol, /hotkeylist, /init, /playlogo.jpg, /stop, /exit, /back, and /playinfo commands."}, {"lang": "es", "value": "Los dispositivos TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, Imperial i400, Imperial i450, Imperial i500-bt y Imperial i600 TN81HH96-g102h-g102, poseen un control de acceso insuficiente para los comandos /set_dname, /mylogo, /LocalPlay, /irdevice.xml, /Sendkey, /setvol, /hotkeylist, /init, /playlogo.jpg, /stop, /exit, /back, y /playinfo."}], "lastModified": "2024-11-21T04:24:58.503", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:telestar:bobs_rock_radio_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E17F5D40-3E6A-4C0B-8F28-5D96F45FE273"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:telestar:bobs_rock_radio:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FF18181F-B99B-483C-B779-38C2C84179D0"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:telestar:dabman_d10_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "68DFF28E-E5AA-4047-AF18-A80A15EC6CEB"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:telestar:dabman_d10:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AF3FE4C9-6A4D-4919-9843-CCC1CB26D67A"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:telestar:dabman_i30_stereo_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "254CA4AF-3CC3-4CDA-AAF5-88835F6B6BFC"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:telestar:dabman_i30_stereo:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "65031EB4-579B-4E6D-9066-27756D021F4E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:telestar:imperial_i110_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "89245799-021A-4D8B-8539-B705BDB39E9B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:telestar:imperial_i110:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FC789F3B-1D46-4646-A798-8ABF326E772E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:telestar:imperial_i150_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F2626170-1D7F-4B16-B6D9-D3015E2444E0"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:telestar:imperial_i150:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "478E93CC-8681-4307-ABBD-1C036FBC61A4"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:telestar:imperial_i200_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D91ADE9C-14DF-44F8-8310-6657482C365D"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:telestar:imperial_i200:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E20E36FC-CD25-4E84-BB9E-E3225C26252A"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:telestar:imperial_i200-cd_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8B9F1D2-9A67-43E3-B0F2-ED657E3444F7"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:telestar:imperial_i200-cd:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3584EFD9-E2F5-4DD2-8CB0-F4F70A095B2B"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:telestar:imperial_i400_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "77C4CBB3-EE19-41FC-BD5C-22B5828D7BE4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:telestar:imperial_i400:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F084C2EF-EDB5-444E-B41C-3D09C844C99D"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:telestar:imperial_i450_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "70788B50-9E5E-4246-A79D-67C0F3BFEF2D"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:telestar:imperial_i450:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7BE2E73A-6C2A-4EE1-ADB3-B91A86BE1138"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:telestar:imperial_i500-bt_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "30B6A1C7-E1AB-4B3C-A074-978F147F9A2B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:telestar:imperial_i500-bt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B854016E-329B-470C-B0AA-6C45109EA81A"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:telestar:imperial_i600_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "414960F2-B667-4949-9534-15C0D71D77DE"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:telestar:imperial_i600:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2E80EDE7-635A-41A9-93FD-17C3D773C3DA"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cve@mitre.org"}