8.8
CVE-2024-22069
- EPSS 0.1%
- Veröffentlicht 08.08.2024 08:15:05
- Zuletzt bearbeitet 20.08.2024 17:22:39
- Quelle psirt@zte.com.cn
- CVE-Watchlists
- Unerledigt
There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the password of the administrator illegally by intercepting requests to change the passwords.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zte ≫ Zxv10 Et301 Firmware Version < v3.22.11p3
Zte ≫ Zxv10 Xt802 Firmware Version < v2.24.10p1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.276 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| psirt@zte.com.cn | 7.1 | 1.3 | 5.3 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:L
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.