8.8
CVE-2019-3425
- EPSS 0.36%
- Veröffentlicht 08.11.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:42:04
- Quelle psirt@zte.com.cn
- CVE-Watchlists
- Unerledigt
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An attacker could exploit this vulnerability to directly reset or change passwords of other accounts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zte ≫ Zxupn-9000e Firmware Version < 9000ev5.0r1b12
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.55 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.