MEDIUM · 5.6

CVE-2018-7356

All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attacke...

Vulnerability Description

All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connections.

CVSS Score

5.6

MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
ZteZxr10 8905E Firmware<= 3.03.10.b23p2
ZteZxr10 8905E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-7356?

CVE-2018-7356 is a vulnerability with a CVSS score of 5.6 (MEDIUM). All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attacke...

How severe is CVE-2018-7356?

CVE-2018-7356 has been rated MEDIUM with a CVSS base score of 5.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-7356?

Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxr10 8905E Firmware, Zte Zxr10 8905E.