CVE-2022-23139
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files.
El producto ZXMP M721 de ZTE presenta una vulnerabilidad de control de permisos y acceso. Ya que el permiso de la carpeta visto por sftp es 666, que es inconsistente con el permiso real. Es fácil que usuarios ignoren la modificación de la configuración de los permisos de los archivos, por lo que las cuentas de baja autoridad podrían obtener permisos de funcionamiento más altos en los archivos clave
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-11 CVE Reserved
- 2022-05-12 CVE Published
- 2023-12-03 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1024444 | 2022-05-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zte Search vendor "Zte" | Zxmp M721 Firmware Search vendor "Zte" for product "Zxmp M721 Firmware" | 5.10.030.006 Search vendor "Zte" for product "Zxmp M721 Firmware" and version "5.10.030.006" | - |
Affected
| in | Zte Search vendor "Zte" | Zxmp M721 Search vendor "Zte" for product "Zxmp M721" | - | - |
Safe
|