Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21726

Опубликовано: 12 мар. 2021
Источник: nvd
CVSS3: 2.3
CVSS2: 2.1
EPSS Низкий

Описание

Some ZTE products have an input verification vulnerability in the diagnostic function interface. Due to insufficient verification of some parameters input by users, an attacker with high privileges can cause process exception by repeatedly inputting illegal parameters. This affects:<ZXONE 9700 , ZXONE 8700, ZXONE 19700><V1.40.021.021CP049, V1.0P02B219_@NCPM-RELEASE_2.40R1-20200914.set>

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:zte:zxone_9700_firmware:1.40.021.021cp049:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxone_9700:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:zte:zxone_8700_firmware:1.40.021.021cp049:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxone_8700:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:zte:zxone_19700_firmware:1.0p02b219_\@ncpm-release_2.40r1-20200914.set:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxone_19700:-:*:*:*:*:*:*:*

EPSS

Процентиль: 16%
0.00051
Низкий

2.3 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
больше 3 лет назад

Some ZTE products have an input verification vulnerability in the diagnostic function interface. Due to insufficient verification of some parameters input by users, an attacker with high privileges can cause process exception by repeatedly inputting illegal parameters. This affects:<ZXONE 9700 , ZXONE 8700, ZXONE 19700><V1.40.021.021CP049, V1.0P02B219_@NCPM-RELEASE_2.40R1-20200914.set>

EPSS

Процентиль: 16%
0.00051
Низкий

2.3 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-20