9.6
CVE-2018-7360
- EPSS 0.1%
- Veröffentlicht 16.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:04
- Quelle psirt@zte.com.cn
- CVE-Watchlists
- Unerledigt
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by information exposure vulnerability, which may allow an unauthenticated attacker to get the GPON SN information via appviahttp service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zte ≫ Zxhn F670 Firmware Version < 1.1.10p3t18
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.249 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 3.3 | 6.5 | 2.9 |
AV:A/AC:L/Au:N/C:P/I:N/A:N
|
| psirt@zte.com.cn | 9.6 | 2.8 | 6 |
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.