CVE-2022-23139

ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zte:zxmp_m721_firmware:5.10.030.006:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxmp_m721:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:48

Type Values Removed Values Added
References () https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1024444 - Vendor Advisory () https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1024444 - Vendor Advisory

23 May 2022, 19:21

Type Values Removed Values Added
CPE cpe:2.3:h:zte:zxmp_m721:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxmp_m721_firmware:5.10.030.006:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 8.8
References (MISC) https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1024444 - (MISC) https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1024444 - Vendor Advisory
CWE CWE-863

12 May 2022, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-12 20:15

Updated : 2024-11-21 06:48


NVD link : CVE-2022-23139

Mitre link : CVE-2022-23139

CVE.ORG link : CVE-2022-23139


JSON object : View

Products Affected

zte

  • zxmp_m721_firmware
  • zxmp_m721
CWE
CWE-863

Incorrect Authorization