CVE-2020-15335: High severity zyxel cloud cnm secumanager vulnerability
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15335?
The severity of CVE-2020-15335 is high with a severity value of 7.5.
Which software versions are affected by CVE-2020-15335?
Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1 are affected by CVE-2020-15335.
How does CVE-2020-15335 impact Zyxel CloudCNM SecuManager?
CVE-2020-15335 allows unauthorized access to the /registerCpe endpoint of Zyxel CloudCNM SecuManager without authentication.
Is there a fix available for CVE-2020-15335?
At the moment, there is no information available about a fix for CVE-2020-15335. It is recommended to apply any patches or updates provided by the vendor and follow their security advisories.
Where can I find more information about CVE-2020-15335?
You can find more information about CVE-2020-15335 on the following references: 1. [CVE-2020-15335 - Zyxel Security Advisory](https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml) 2. [Zyxel SecuManager 0day Vulnerabilities - Blog Post by Pierre Kim](https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html#xmpp-no-auth-cleartext)