CVE-2015-7255
 
Severity Score
7.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device.
ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, y ZXHN H108N utilizan certificados X.509 no únicos y claves de host SSH, lo que puede permitir a los atacantes remotos que obtengan credenciales u otra información sensible a través de un ataque Man-in-the-Middle (MitM), un ataque de descifrado pasivo o mediante la suplantación de un dispositivo legítimo.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2015-09-18 CVE Reserved
- 2017-08-29 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.kb.cert.org/vuls/id/566724 | Mitigation | |
https://github.com/sec-consult/houseofkeys/search?p=3&q=zte&type=&utf8=%E2%9C%93 | Third Party Advisory | |
https://www.kb.cert.org/vuls/id/BLUU-A2NQYR | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zte Search vendor "Zte" | Ox-330p Firmware Search vendor "Zte" for product "Ox-330p Firmware" | - | - |
Affected
| in | Zte Search vendor "Zte" | Ox-330p Search vendor "Zte" for product "Ox-330p" | - | - |
Safe
|
Zte Search vendor "Zte" | Zxhn H108n Firmware Search vendor "Zte" for product "Zxhn H108n Firmware" | - | - |
Affected
| in | Zte Search vendor "Zte" | Zxhn H108n Search vendor "Zte" for product "Zxhn H108n" | - | - |
Safe
|
Zte Search vendor "Zte" | W300v1.0.0s Zrd Tr1 D68 Firmware Search vendor "Zte" for product "W300v1.0.0s Zrd Tr1 D68 Firmware" | - | - |
Affected
| in | Zte Search vendor "Zte" | W300v1.0.0s Zrd Tr1 D68 Search vendor "Zte" for product "W300v1.0.0s Zrd Tr1 D68" | - | - |
Safe
|
Zte Search vendor "Zte" | Hg110 Firmware Search vendor "Zte" for product "Hg110 Firmware" | - | - |
Affected
| in | Zte Search vendor "Zte" | Hg110 Search vendor "Zte" for product "Hg110" | - | - |
Safe
|
Zte Search vendor "Zte" | Gan9.8t101a-b Firmware Search vendor "Zte" for product "Gan9.8t101a-b Firmware" | - | - |
Affected
| in | Zte Search vendor "Zte" | Gan9.8t101a-b Search vendor "Zte" for product "Gan9.8t101a-b" | - | - |
Safe
|
Zte Search vendor "Zte" | Mf28g Firmware Search vendor "Zte" for product "Mf28g Firmware" | - | - |
Affected
| in | Zte Search vendor "Zte" | Mf28g Search vendor "Zte" for product "Mf28g" | - | - |
Safe
|
Zte Search vendor "Zte" | Zxhn H108n Firmware Search vendor "Zte" for product "Zxhn H108n Firmware" | - | - |
Affected
| in | Zte Search vendor "Zte" | Zxhn H108n Search vendor "Zte" for product "Zxhn H108n" | - | - |
Safe
|