PT-2020-14371 · Zyxel · Zyxel Cloudcnm Secumanager

Alexandre Torres

+1

·

Published

2020-06-26

·

Updated

2022-10-27

·

CVE-2020-15337

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zyxel CloudCNM SecuManager versions 3.1.0 through 3.1.1
Description The issue is related to the use of GET request method with sensitive query strings for /registerCpe requests. This can potentially expose sensitive information.
Recommendations For versions 3.1.0 and 3.1.1, consider restricting access to the /registerCpe endpoint until a fix is available. As a temporary workaround, avoid using sensitive query strings in the /registerCpe requests. Restrict access to sensitive information that may be exposed through the /registerCpe endpoint.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15337

Affected Products

Zyxel Cloudcnm Secumanager