PT-2019-16580 · Zte · Zxcdn Iamweb
Publicado
2019-11-22
·
Atualizado
2022-03-31
·
CVE-2019-3428
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ZTE ZXCDN IAMWEB version V6.01.03.01
Description
The issue is related to a configuration error, allowing an attacker to directly access the management portal over HTTP. This could result in the leakage of users' information.
Recommendations
For version V6.01.03.01, consider configuring the management portal to use HTTPS instead of HTTP to encrypt the communication and prevent information leakage. Additionally, review and update the configuration to prevent direct access to the management portal.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Zxcdn Iamweb