First published: Mon Dec 23 2019(Updated: )
All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
ZTE ZXCLOUD GoldenData VAP | <=zxivs-vap-portal-xzgav4.01.01.02 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3431 is classified as a high severity vulnerability due to its potential for credential theft.
To fix CVE-2019-3431, upgrade the ZTE ZXCLOUD GoldenData VAP to version V4.01.01.02 or later, ensuring proper encryption is enabled.
CVE-2019-3431 allows attackers to intercept unencrypted user credentials, compromising front-end system access.
Any version of ZTE ZXCLOUD GoldenData VAP up to and including V4.01.01.02 is affected by CVE-2019-3431.
CVE-2019-3431 can be exploited by any remote attacker with access to the network traffic where the vulnerable system operates.