PT-2020-14380 · Zyxel · Zyxel Cloudcnm Secumanager

Alexandre Torres

+1

·

Published

2020-06-26

·

Updated

2021-07-21

·

CVE-2020-15348

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel CloudCNM SecuManager versions 3.1.0 through 3.1.1
Description The issue allows for the injection of Python code through the "live/CPEManager/AXCampaignManager/delete cpes by ids" API endpoint, specifically by manipulating the cpe ids variable. This could potentially lead to unauthorized code execution.
Recommendations For versions 3.1.0 and 3.1.1, consider restricting access to the "live/CPEManager/AXCampaignManager/delete cpes by ids" API endpoint to minimize the risk of exploitation. Avoid using the cpe ids variable in the affected API endpoint until the issue is resolved.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15348

Affected Products

Zyxel Cloudcnm Secumanager