CVE-2017-10930
moderate-risk
Published 2017-09-19
The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in ordinary users being able to download configuration files to steal information like administrator accounts and passwords.
Do I need to act?
-
0.33% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (4)
Zxr10 160 Firmware
Zxr10 1800-2S Firmware
Zxr10 2800-4 Firmware
Zxr10 3800-8 Firmware
Affected Vendors
References (2)
Permissions Required
http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008262
Permissions Required
http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008262
43
/ 100
moderate-risk
Severity
32/34 · Critical
Exploitability
1/34 · Minimal
Exposure
10/34 · Low