PT-2020-14361 · Zyxel · Zyxel Cloudcnm Secumanager

Alexandre Torres

+2

·

Published

2020-06-29

·

Updated

2020-07-06

·

CVE-2020-15324

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zyxel CloudCNM SecuManager versions 3.1.0 through 3.1.1
Description The issue concerns a world-readable file that stores hardcoded credentials. The file in question is xmpp config.py, located at axess/opt/axXMPPHandler/config/. This poses a significant security risk as it potentially exposes sensitive information.
Recommendations For versions 3.1.0 and 3.1.1, consider restricting access to the xmpp config.py file to prevent unauthorized reading of the hardcoded credentials. As a temporary workaround, changing the file permissions to limit access can help mitigate the risk until a more permanent solution is available.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15324

Affected Products

Zyxel Cloudcnm Secumanager