CVE-2022-23141

ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled, an attacker could use this vulnerability to log in to the device to obtain sensitive information.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zte:zxmp_m721_firmware:commond21bootv100004_ls1045:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxmp_m721:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:48

Type Values Removed Values Added
References () https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1025264 - Vendor Advisory () https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1025264 - Vendor Advisory

Information

Published : 2022-07-15 15:15

Updated : 2024-11-21 06:48


NVD link : CVE-2022-23141

Mitre link : CVE-2022-23141

CVE.ORG link : CVE-2022-23141


JSON object : View

Products Affected

zte

  • zxmp_m721
  • zxmp_m721_firmware
CWE
CWE-532

Insertion of Sensitive Information into Log File