PT-2019-16580 · Zte · Zxcdn Iamweb
Published
2019-11-22
·
Updated
2022-03-31
·
CVE-2019-3428
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ZTE ZXCDN IAMWEB version V6.01.03.01
Description
The issue is related to a configuration error, allowing an attacker to directly access the management portal over HTTP. This could result in the leakage of users' information.
Recommendations
For version V6.01.03.01, consider configuring the management portal to use HTTPS instead of HTTP to encrypt the communication and prevent information leakage. Additionally, review and update the configuration to prevent direct access to the management portal.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zxcdn Iamweb