PT-2020-6757 · Zyxel · Zyxel Cloudcnm Secumanager
Alexandre Torres
+1
·
Published
2020-06-26
·
Updated
2022-10-27
·
CVE-2020-15332
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zyxel CloudCNM SecuManager versions 3.1.0 through 3.1.1
Description
The issue is related to weak permissions of the /opt/axess/etc/default/axess file in the Zyxel CloudCNM SecuManager software, which is used for centralized device management in networks. This weakness is associated with the unencrypted storage of credentials. Exploitation of this issue could allow a remote attacker to gain full access to devices on the network.
Recommendations
For versions 3.1.0 and 3.1.1, consider restricting access to the /opt/axess/etc/default/axess file to minimize the risk of exploitation.
As a temporary workaround, avoid using the affected file until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Cloudcnm Secumanager