CVE-2020-15348: Code Injection
Published Jun 26, 2020
·Updated
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows use of live/CPEManager/AXCampaignManager/deletecpesbyids?cpeids= for eval injection of Python code.
Affected Software
2 affected components
Zyxel Cloud Cnm Secumanager=3.1.0
Zyxel Cloud Cnm Secumanager=3.1.1
Event History
Jun 26, 2020
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-15348?
CVE-2020-15348 is considered a critical vulnerability due to its potential for remote code execution via eval injection.
2
How do I fix CVE-2020-15348?
To fix CVE-2020-15348, upgrade Zyxel CloudCNM SecuManager to version 3.1.2 or later to eliminate the vulnerability.
3
What versions of Zyxel CloudCNM SecuManager are affected by CVE-2020-15348?
Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1 are affected by CVE-2020-15348.
4
What can be exploited in CVE-2020-15348?
CVE-2020-15348 can be exploited to execute arbitrary Python code on the server due to improper input validation.
5
Is there any mitigation for CVE-2020-15348?
As a temporary mitigation for CVE-2020-15348, restrict access to the affected endpoints until the software is updated to a secure version.