CVE-2022-23138
 
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the device is reduced, and it may face the risk of attack.
El producto MF297D de ZTE presenta una vulnerabilidad de problemas criptográficos. Debido al uso de valores aleatorios débiles, la seguridad del dispositivo es reducida, y puede enfrentarse al riesgo de ataque
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-01-11 CVE Reserved
- 2022-06-09 CVE Published
- 2023-12-31 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-330: Use of Insufficiently Random Values
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1024624 | 2022-06-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zte Search vendor "Zte" | Mf297d Firmware Search vendor "Zte" for product "Mf297d Firmware" | mf297d_nordic1_b05 Search vendor "Zte" for product "Mf297d Firmware" and version "mf297d_nordic1_b05" | - |
Affected
| in | Zte Search vendor "Zte" | Mf297d Search vendor "Zte" for product "Mf297d" | - | - |
Safe
|