Zyxel
Zyxel Cloudcnm Secumanager: vulnerabilidades y CVE
Zyxel Cloudcnm Secumanager tiene 35 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 7 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE35
Últimos 12 meses0
Críticas7
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-15347 | Crítica (9.8) | 1.3% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account. |
| CVE-2020-15346 | Media (5.3) | 0.57% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key. |
| CVE-2020-15345 | Media (5.3) | 0.57% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API. |
| CVE-2020-15344 | Media (5.3) | 0.57% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API. |
| CVE-2020-15343 | Media (5.3) | 0.58% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API. |
| CVE-2020-15342 | Media (5.3) | 0.56% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API. |
| CVE-2020-15341 | Alta (7.5) | 1.1% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API. |
| CVE-2020-15340 | Alta (7.5) | 0.74% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key. |
| CVE-2020-15339 | Media (6.1) | 0.71% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_name= XSS. |
| CVE-2020-15338 | Media (5.3) | 0.76% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests. |
| CVE-2020-15337 | Media (5.3) | 0.79% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests. |
| CVE-2020-15334 | Media (5.3) | 0.78% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file. |
| CVE-2020-15333 | Media (5.3) | 0.95% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Users_users" requests. |
| CVE-2020-15332 | Crítica (9.8) | 0.89% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions. |
| CVE-2020-15331 | Crítica (9.8) | 0.89% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess. |
| CVE-2020-15330 | Media (5.3) | 0.57% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess. |
| CVE-2020-15329 | Media (5.3) | 0.85% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions. |
| CVE-2020-15328 | Media (5.3) | 0.85% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions. |
| CVE-2020-15327 | Alta (7.5) | 0.96% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication. |
| CVE-2020-15326 | Media (5.3) | 0.53% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem. |
| CVE-2020-15325 | Media (5.3) | 0.57% | — | 29 sept 2022 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication. |
| CVE-2020-15323 | Crítica (9.8) | 1.3% | — | 29 jun 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials. |
| CVE-2020-15322 | Crítica (9.8) | 1.3% | — | 29 jun 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account. |
| CVE-2020-15321 | Crítica (9.8) | 1.3% | — | 29 jun 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account. |
| CVE-2020-15320 | Crítica (9.8) | 1.3% | — | 29 jun 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account. |
| CVE-2020-15319 | Media (5.9) | 1.00% | — | 29 jun 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/mysql chroot directory tree. |
| CVE-2020-15318 | Media (5.9) | 1.00% | — | 29 jun 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/mysql chroot directory tree. |
| CVE-2020-15317 | Media (5.9) | 0.98% | — | 29 jun 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account within the /opt/axess chroot directory tree. |
| CVE-2020-15316 | Media (5.9) | 0.98% | — | 29 jun 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree. |
| CVE-2020-15315 | Media (5.9) | 0.98% | — | 29 jun 2020 | Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account within the /opt/axess chroot directory tree. |
Otros productos de Zyxel
Gs1900-10hp Firmware · 35USG Flex 200 Firmware · 34USG Flex 500 Firmware · 34USG Flex 100w Firmware · 34USG Flex 700 Firmware · 34USG Flex 100 Firmware · 30Emg3525-t50b Firmware · 28Emg5523-t50b Firmware · 28Vmg8623-t50b Firmware · 28USG Flex 50W Firmware · 26Atp500 Firmware · 25Atp200 Firmware · 25