9.8

CVE-2017-10930

The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZteZxr10 1800-2s Firmware Version < 3.00.40
   ZteZxr10 1800-2s Version-
ZteZxr10 2800-4 Firmware Version < 3.00.40
   ZteZxr10 2800-4 Version-
ZteZxr10 3800-8 Firmware Version < 3.00.40
   ZteZxr10 3800-8 Version-
ZteZxr10 160 Firmware Version < 3.00.40
   ZteZxr10 160 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.527
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.