CVE-2020-15324: Critical severity zyxel cloud cnm secumanager vulnerability
Published Jun 29, 2020
·Updated
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmppconfig.py file that stores hardcoded credentials.
Affected Software
2 affected components
Zyxel Cloud Cnm Secumanager=3.1.0
Zyxel Cloud Cnm Secumanager=3.1.1
Event History
Jun 29, 2020
CVE Published
via MITRE·03:29 PM
Data Sourced
via MITRE·03:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-15324?
CVE-2020-15324 has been rated as a critical severity vulnerability due to the exposure of hardcoded credentials.
2
How do I fix CVE-2020-15324?
To fix CVE-2020-15324, update Zyxel CloudCNM SecuManager to version 3.1.2 or later.
3
What is the impact of CVE-2020-15324?
CVE-2020-15324 allows unauthorized users to access sensitive configuration information, potentially leading to exploitation of the Zyxel device.
4
Which versions of Zyxel CloudCNM SecuManager are affected by CVE-2020-15324?
CVE-2020-15324 affects Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1.
5
What are the hardcoded credentials exposed in CVE-2020-15324?
CVE-2020-15324 exposes hardcoded credentials stored in the xmpp_config.py file, which can be accessed by anyone with read permissions.