CVE-2022-23141: High severity zte zxmp m721 dx firmware vulnerability
Published Jul 15, 2022
·Updated
ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled, an attacker could use this vulnerability to log in to the device to obtain sensitive information.
Affected Software
2 affected components
ZTE Zxmp M721 Firmware=commond21bootv100004_ls1045
ZTE ZXMP M721
Event History
Jul 15, 2022
CVE Published
via MITRE·02:44 PM
Data Sourced
via MITRE·02:44 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-23141?
CVE-2022-23141 is an information leak vulnerability in ZXMP M721.
2
What is the severity of CVE-2022-23141?
The severity of CVE-2022-23141 is high, with a CVSS score of 7.5.
3
How does CVE-2022-23141 affect Zte Zxmp M721 firmware?
CVE-2022-23141 affects Zte Zxmp M721 firmware version commond21bootv100004_ls1045.
4
How can an attacker exploit CVE-2022-23141?
An attacker can exploit CVE-2022-23141 by logging in to the device through the ineffective serial port authentication on the ZBOOT interface.
5
Is Zte Zxmp M721 vulnerable to CVE-2022-23141?
Yes, Zte Zxmp M721 is vulnerable to CVE-2022-23141.