Логотип exploitDog
bind:CVE-2022-23139
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-23139

Количество 2

Количество 2

nvd логотип

CVE-2022-23139

больше 3 лет назад

ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-7xpx-4ggr-whc7

больше 3 лет назад

ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-23139

ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-7xpx-4ggr-whc7

ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу