Vulnerability Description
ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled, an attacker could use this vulnerability to log in to the device to obtain sensitive information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Zxmp M721 Firmware | commond21bootv100004_ls1045 |
| Zte | Zxmp M721 | - |
Related Weaknesses (CWE)
References
- https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1025264Vendor Advisory
- https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1025264Vendor Advisory
FAQ
What is CVE-2022-23141?
CVE-2022-23141 is a vulnerability with a CVSS score of 7.5 (HIGH). ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled, an attacker could use this vulnerability to log in...
How severe is CVE-2022-23141?
CVE-2022-23141 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23141?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Zxmp M721 Firmware, Zte Zxmp M721.