« Volver al listado

CVE-2021-21750

Estado: ModificadaAlta (7.8)—

ZTE BigVideo Analysis product has a privilege escalation vulnerability. Due to improper management of the timed task modification privilege, an attacker with ordinary user permissions could exploit this vulnerability to gain unauthorized access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-21750",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@zte.com.cn",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "ZXIN10 CMS",
          "versions": [
            {
              "status": "affected",
              "version": "All versions up to ZXOMS-BIGDATA-IOPSWEBV3.01.01.04"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-12-27T19:15:08.013",
  "references": [
    {
      "url": "https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1021884",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@zte.com.cn"
    },
    {
      "url": "https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1021884",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "ZTE BigVideo Analysis product has a privilege escalation vulnerability. Due to improper management of the timed task modification privilege, an attacker with ordinary user permissions could exploit this vulnerability to gain unauthorized access."
    },
    {
      "lang": "es",
      "value": "El producto ZTE BigVideo Analysis presenta una vulnerabilidad de escalada de privilegios. Debido a la administración inapropiada del privilegio de modificación de la tarea temporizada, un atacante con permisos de usuario ordinario podría explotar esta vulnerabilidad para conseguir un acceso no autorizado"
    }
  ],
  "lastModified": "2026-06-17T03:36:05.323",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zte:zxin10_cms:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8511EFB2-B29D-494F-8689-AF1E0804BF77",
              "versionEndIncluding": "3.01.01.04"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@zte.com.cn"
}