Products
ZTE H388X
Source
psirt@zte.com.cn
Tags
CVE-2023-25646 details
Published : June 20, 2024, 7:15 a.m.
Last Modified : June 20, 2024, 12:43 p.m.
Last Modified : June 20, 2024, 12:43 p.m.
Description
There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this vulnerability to obtain elevated permissions on the affected device by performing specific operations.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7.1 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-281 | Improper Preservation of Permissions | The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended. |
CVSS Data
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
7.1
Exploitability Score
0.5
Impact Score
6.0
Base Severity
HIGH
Vector String : CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
References
URL | Source |
---|---|
https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1035844 | psirt@zte.com.cn |
This website uses the NVD API, but is not approved or certified by it.