CVE-2017-10934: Critical severity zte zxiptv vulnerability
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10934?
CVE-2017-10934 is considered a critical vulnerability that allows unauthenticated remote attackers to exploit Java deserialization issues.
How do I fix CVE-2017-10934?
To fix CVE-2017-10934, upgrade to ZTE ZXIPTV-EPG version 5.09.02.02T4 or later.
Which versions of ZTE ZXIPTV-EPG are affected by CVE-2017-10934?
All versions of ZTE ZXIPTV-EPG prior to version 5.09.02.02T4 are affected by CVE-2017-10934.
Can attackers exploit CVE-2017-10934 without authentication?
Yes, attackers can exploit CVE-2017-10934 without authentication due to the remote nature of the vulnerability.
What type of vulnerability is CVE-2017-10934?
CVE-2017-10934 is a Java deserialization vulnerability involving the Apache Commons Collections library.