CVE-2020-15342: Medium severity zyxel cloud cnm secumanager vulnerability
Published Jun 26, 2020
·Updated
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zyinstalluser API.
Affected Software
2 affected components
Zyxel Cloud CNM SecuManager=3.1.0
Zyxel Cloud CNM SecuManager=3.1.1
Event History
Jun 26, 2020
CVE Published
via MITRE·02:56 PM
Data Sourced
via MITRE·02:56 PM
Description
Frequently Asked Questions
1
What is CVE-2020-15342?
CVE-2020-15342 refers to an unauthenticated zy_install_user API vulnerability in Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1.
2
How severe is CVE-2020-15342?
CVE-2020-15342 has a severity score of 5.3, which is considered medium.
3
Which software versions are affected by CVE-2020-15342?
Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1 are affected by CVE-2020-15342.
4
What is the Common Weakness Enumeration (CWE) for CVE-2020-15342?
CVE-2020-15342 is associated with CWE-311, which is related to missing encryption of sensitive data.
5
Where can I find more information and updates about CVE-2020-15342?
You can find more information and updates about CVE-2020-15342 on the following resources: [link_1](https://pierrekim.github.io/blog/2020-03-09-zyxel-secumanager-0day-vulnerabilities.html), [link_2](https://www.zyxel.com/support/vulnerabilities-of-CloudCNM-SecuManager.shtml).