LOW · 2.3

CVE-2021-21726

Some ZTE products have an input verification vulnerability in the diagnostic function interface. Due to insufficient verification of some parameters input by users, an attacker with high privileges ca...

Vulnerability Description

Some ZTE products have an input verification vulnerability in the diagnostic function interface. Due to insufficient verification of some parameters input by users, an attacker with high privileges can cause process exception by repeatedly inputting illegal parameters. This affects:<ZXONE 9700 , ZXONE 8700, ZXONE 19700><V1.40.021.021CP049, V1.0P02B219_@NCPM-RELEASE_2.40R1-20200914.set>

CVSS Score

2.3

LOW

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
ZteZxone 9700 Firmware1.40.021.021cp049
ZteZxone 9700-
ZteZxone 8700 Firmware1.40.021.021cp049
ZteZxone 8700-
ZteZxone 19700 Firmware1.0p02b219_\@ncpm-release_2.40r1-20200914.set
ZteZxone 19700-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-21726?

CVE-2021-21726 is a vulnerability with a CVSS score of 2.3 (LOW). Some ZTE products have an input verification vulnerability in the diagnostic function interface. Due to insufficient verification of some parameters input by users, an attacker with high privileges ca...

How severe is CVE-2021-21726?

CVE-2021-21726 has been rated LOW with a CVSS base score of 2.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-21726?

Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxone 9700 Firmware, Zte Zxone 9700, Zte Zxone 8700 Firmware, Zte Zxone 8700, Zte Zxone 19700 Firmware.