ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device.
References
Link | Resource |
---|---|
http://www.kb.cert.org/vuls/id/566724 | Mitigation Third Party Advisory US Government Resource |
https://github.com/sec-consult/houseofkeys/search?p=3&q=zte&type=&utf8=%E2%9C%93 | Third Party Advisory |
https://www.kb.cert.org/vuls/id/BLUU-A2NQYR | Third Party Advisory US Government Resource |
http://www.kb.cert.org/vuls/id/566724 | Mitigation Third Party Advisory US Government Resource |
https://github.com/sec-consult/houseofkeys/search?p=3&q=zte&type=&utf8=%E2%9C%93 | Third Party Advisory |
https://www.kb.cert.org/vuls/id/BLUU-A2NQYR | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
History
21 Nov 2024, 02:36
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.kb.cert.org/vuls/id/566724 - Mitigation, Third Party Advisory, US Government Resource | |
References | () https://github.com/sec-consult/houseofkeys/search?p=3&q=zte&type=&utf8=%E2%9C%93 - Third Party Advisory | |
References | () https://www.kb.cert.org/vuls/id/BLUU-A2NQYR - Third Party Advisory, US Government Resource |
Information
Published : 2017-08-29 15:29
Updated : 2024-11-21 02:36
NVD link : CVE-2015-7255
Mitre link : CVE-2015-7255
CVE.ORG link : CVE-2015-7255
JSON object : View
Products Affected
zte
- ox-330p_firmware
- w300v1.0.0s_zrd_tr1_d68
- zxhn_h108n_firmware
- mf28g
- mf28g_firmware
- w300v1.0.0s_zrd_tr1_d68_firmware
- gan9.8t101a-b
- zxhn_h108n
- ox-330p
- gan9.8t101a-b_firmware
- hg110_firmware
- hg110
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor