HIGH · 8.8

CVE-2019-3425

The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An attacker could exploit this vulnerability to directly...

Vulnerability Description

The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An attacker could exploit this vulnerability to directly reset or change passwords of other accounts.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ZteZxupn-9000E Firmware< 9000ev5.0r1b12
ZteZxupn-9000E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-3425?

CVE-2019-3425 is a vulnerability with a CVSS score of 8.8 (HIGH). The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An attacker could exploit this vulnerability to directly...

How severe is CVE-2019-3425?

CVE-2019-3425 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-3425?

Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxupn-9000E Firmware, Zte Zxupn-9000E.