Vulnerability Description
All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the original password authentication protection to change other user's password.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Zxr10 1800-2S Firmware | < 3.00.40 |
| Zte | Zxr10 1800-2S | - |
References
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008723MitigationVendor Advisory
- http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1008723MitigationVendor Advisory
FAQ
What is CVE-2017-10935?
CVE-2017-10935 is a vulnerability with a CVSS score of 7.2 (HIGH). All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the original password authentication protection to change other user's password.
How severe is CVE-2017-10935?
CVE-2017-10935 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-10935?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxr10 1800-2S Firmware, Zte Zxr10 1800-2S.