8.8
CVE-2024-22067
- EPSS 0.22%
- Veröffentlicht 18.11.2024 07:15:17
- Zuletzt bearbeitet 13.03.2025 17:15:28
- Quelle psirt@zte.com.cn
- Teams Watchlist Login
- Unerledigt Login
ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the vulnerability to execute arbitrary commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zte ≫ Nh8091 Firmware Versionznh8091v1.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.22% | 0.444 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
psirt@zte.com.cn | 6.8 | 0.9 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.