First published: Mon Dec 23 2019(Updated: )
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could obtain log file information without authorization, causing the disclosure of sensitive information.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
ZTE ZXCLOUD GoldenData VAP | <=zxivs-vap-portal-xzgav4.01.01.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3429 is considered a high severity vulnerability due to unauthorized access to sensitive log file information.
To fix CVE-2019-3429, you should update to a version of ZTE ZXCLOUD GoldenData VAP that is newer than V4.01.01.02.
CVE-2019-3429 is categorized as a file reading vulnerability.
Attackers exploiting CVE-2019-3429 could gain unauthorized access to sensitive information contained in log files.
All versions of ZTE ZXCLOUD GoldenData VAP up to and including V4.01.01.02 are affected by CVE-2019-3429.