First published: Mon Dec 05 2022(Updated: )
ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an attacker with high permissions could use this vulnerability to maliciously delete and modify files.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
Zte Otcp Firmware | <2.21.40.06 | |
ZTE OTCP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23143 is a permission and access control vulnerability in the ZTE OTCP product.
CVE-2022-23143 affects ZTE OTCP firmware version up to exclusive 2.21.40.06.
An attacker with high permissions can maliciously delete and modify files using CVE-2022-23143.
CVE-2022-23143 has a severity rating of 6.5 (medium).
To fix CVE-2022-23143, it is recommended to apply the latest updates and patches provided by ZTE.