PT-2020-6757 · Zyxel · Zyxel Cloudcnm Secumanager

Alexandre Torres

+1

·

Published

2020-06-26

·

Updated

2022-10-27

·

CVE-2020-15332

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel CloudCNM SecuManager versions 3.1.0 through 3.1.1
Description The issue is related to weak permissions of the /opt/axess/etc/default/axess file in the Zyxel CloudCNM SecuManager software, which is used for centralized device management in networks. This weakness is associated with the unencrypted storage of credentials. Exploitation of this issue could allow a remote attacker to gain full access to devices on the network.
Recommendations For versions 3.1.0 and 3.1.1, consider restricting access to the /opt/axess/etc/default/axess file to minimize the risk of exploitation. As a temporary workaround, avoid using the affected file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2022-06062
CVE-2020-15332

Affected Products

Zyxel Cloudcnm Secumanager