CVE-2021-21739

A ZTE's product of the transport network access layer has a security vulnerability. Because the system does not sufficiently verify the data reliability, attackers could replace an authenticated optical module on the equipment with an unauthenticated one, bypassing system authentication and detection, thus affecting signal transmission. This affects: <ZXCTN 6120H><V5.10.00B24>
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zte:zxctn_6120h_firmware:5.10.00b24:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxctn_6120h:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:48

Type Values Removed Values Added
References () https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1017024 - Vendor Advisory () https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1017024 - Vendor Advisory

Information

Published : 2021-08-05 20:15

Updated : 2024-11-21 05:48


NVD link : CVE-2021-21739

Mitre link : CVE-2021-21739

CVE.ORG link : CVE-2021-21739


JSON object : View

Products Affected

zte

  • zxctn_6120h_firmware
  • zxctn_6120h
CWE
CWE-345

Insufficient Verification of Data Authenticity