Page 27 of 280 results (0.007 seconds)

CVSS: 5.9EPSS: 0%CPEs: 2EXPL: 1

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta una clave SSH DSA embebida para la cuenta root • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml • CWE-798: Use of Hard-coded Credentials •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 1

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta permisos débiles en /opt/axess/etc/default/axess • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml • CWE-312: Cleartext Storage of Sensitive Information •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 1

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Users_users" requests. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, permite a atacantes detectar cuentas por medio de peticiones MySQL "select * from Administrator_users" y "select * from Users_users" • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 5.3EPSS: 0%CPEs: 2EXPL: 1

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, permite una inyección de secuencias de escape en el archivo /var/log/axxmpp.log • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, no posee autenticación para las peticiones /registerCpe • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html#xmpp-no-auth-cleartext https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml • CWE-306: Missing Authentication for Critical Function •