CVE-2023-25648: Weak Folder Permission Vulnerability in ZTE ZXCLOUD iRAI
Published Dec 14, 2023
·Updated
There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.
Affected Software
2 affected components
All of the following
ZTE ZXCLOUD iRAI<7.23.21
ZTE ZXCLOUD iRAI
Remediation
Information
ZXCLOUD iRAI V7.23.21
Event History
Dec 14, 2023
CVE Published
06:46 AM
Data Sourced
06:46 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-25648?
CVE-2023-25648 has been classified as a vulnerability with a potential for privilege escalation due to weak folder permissions.
2
How do I fix CVE-2023-25648?
To fix CVE-2023-25648, ensure that folder permissions are properly configured to prevent unauthorized access.
3
What are the potential impacts of CVE-2023-25648?
The potential impacts of CVE-2023-25648 include unauthorized command execution and escalation of user privileges.
4
Which software is affected by CVE-2023-25648?
CVE-2023-25648 affects ZTE's ZXCLOUD iRAI product versions up to 7.23.21.
5
Who can exploit CVE-2023-25648?
An attacker with ordinary user privileges can exploit CVE-2023-25648 to escalate their permissions.