NVD: fully analised CVE

Subscribe to NVD: fully analised CVE hírcsatorna
This feed contains the most recent CVE cyber vulnerabilities published within the National Vulnerability Database.
Frissítve: 52 perc 44 másodperc
2022. szeptember 29.

CVE-2020-15327 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.
2022. szeptember 29.

CVE-2020-15328 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions.
2022. szeptember 29.

CVE-2020-15329 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions.
2022. szeptember 29.

CVE-2020-15330 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess.
2022. szeptember 29.

CVE-2020-15331 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.
2022. szeptember 29.

CVE-2020-15332 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
2022. szeptember 29.

CVE-2020-15333 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Users_users" requests.
2022. szeptember 29.

CVE-2020-15334 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file.
2022. szeptember 29.

CVE-2020-15337 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests.
2022. szeptember 29.

CVE-2020-15338 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests.
2022. szeptember 29.

CVE-2020-15339 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_name= XSS.
2022. szeptember 29.

CVE-2020-15340 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key.
2022. szeptember 29.

CVE-2020-15341 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.
2022. szeptember 29.

CVE-2020-15342 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.
2022. szeptember 29.

CVE-2020-15343 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.
2022. szeptember 29.

CVE-2020-15344 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.
2022. szeptember 29.

CVE-2020-15345 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API.
2022. szeptember 29.

CVE-2020-15346 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key.
2022. szeptember 29.

CVE-2020-15347 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.
2022. szeptember 29.

CVE-2020-15325 (cloudcnm_secumanager)

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.