CVE-2020-15336: High severity zyxel cloud cnm secumanager vulnerability
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-15336.
What is the severity of CVE-2020-15336?
The severity of CVE-2020-15336 is high with a severity value of 7.5.
What is the affected software?
The affected software is Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1.
What is the recommended action to fix this vulnerability?
To fix this vulnerability, it is recommended to update Zyxel CloudCNM SecuManager to a version that includes the necessary authentication for /cnr requests.
Where can I find more information about CVE-2020-15336?
You can find more information about CVE-2020-15336 at the following references: [https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html#xmpp-no-auth-cleartext](https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html#xmpp-no-auth-cleartext) and [https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml](https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml).