9.1

CVE-2022-23144

There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission control, attackers could use this vulnerability to delete the default application type, which affects normal use of system.

Data is provided by the National Vulnerability Database (NVD)
ZteZxa10 B76hv3 Firmware Version <= 2.01.02.01
   ZteZxa10 B76hv3 Version-
ZteZxa10 B766v2 Firmware Version <= 2.01.02.01
   ZteZxa10 B766v2 Version-
ZteZxa10 B800v2 Firmware Version <= 2.01.02.01
   ZteZxa10 B800v2 Version-
ZteZxa10 B860av2.1 Firmware Version <= 2.01.02.01
   ZteZxa10 B860av2.1 Version-
ZteZxa10 B860h Firmware Version <= 2.01.02.01
   ZteZxa10 B860h Version-
ZteZxa10 B866v2-h Firmware Version <= 2.01.02.01
   ZteZxa10 B866v2-h Version-
ZteZxa10 B866v5-w10 Firmware Version <= 2.01.02.01
   ZteZxa10 B866v5-w10 Version-
ZteZxa10 B960gv1 Firmware Version <= 2.01.02.01
   ZteZxa10 B960gv1 Version-
ZteZxa10 B710c-a12 Firmware Version <= 2.01.02.01
   ZteZxa10 B710c-a12 Version-
ZteZxa10 B710s2-a19 Firmware Version <= 2.01.02.01
   ZteZxa10 B710s2-a19 Version-
ZteZxa10 B836ct-a15 Firmware Version <= 2.01.02.01
   ZteZxa10 B836ct-a15 Version-
ZteZxa10 S100v Firmware Version <= 2.01.02.01
   ZteZxa10 S100v Version-
ZteZxa10 S200a Firmware Version <= 2.01.02.01
   ZteZxa10 S200a Version-
ZteZxa10 S200t Firmware Version <= 2.01.02.01
   ZteZxa10 S200t Version-
ZteZxa10 B700v7 Firmware Version <= 2.01.02.01
   ZteZxa10 B700v7 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.39% 0.593
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H