CVE-2020-15313
https://notcve.org/view.php?id=CVE-2020-15313
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta una clave SSH ECDSA embebida para la cuenta root • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml • CWE-798: Use of Hard-coded Credentials •
CVE-2020-15312
https://notcve.org/view.php?id=CVE-2020-15312
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta una clave SSH DSA embebida para la cuenta root • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml • CWE-798: Use of Hard-coded Credentials •
CVE-2020-15332
https://notcve.org/view.php?id=CVE-2020-15332
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, presenta permisos débiles en /opt/axess/etc/default/axess • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml • CWE-312: Cleartext Storage of Sensitive Information •
CVE-2020-15333
https://notcve.org/view.php?id=CVE-2020-15333
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Users_users" requests. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, permite a atacantes detectar cuentas por medio de peticiones MySQL "select * from Administrator_users" y "select * from Users_users" • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2020-15334
https://notcve.org/view.php?id=CVE-2020-15334
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file. Zyxel CloudCNM SecuManager versiones 3.1.0 y 3.1.1, permite una inyección de secuencias de escape en el archivo /var/log/axxmpp.log • https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml •