CVE-2024-22062: Permissions and Access Control Vulnerability in ZTE ZXCLOUD IRAI
Published Jul 9, 2024
·Updated
There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.
Affected Software
2 affected components
ZTE ZXCLOUD iRAI<7.23.40
ZTE ZXCLOUD iRAI
Remediation
Information
ClientV7.23.40
Event History
Jul 9, 2024
CVE Published
via MITRE·06:41 AM
Data Sourced
via MITRE·06:41 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-22062?
CVE-2024-22062 has a high severity rating due to the potential for unauthorized privilege escalation.
2
How do I fix CVE-2024-22062?
To fix CVE-2024-22062, update ZTE ZXCLOUD IRAI to version 7.23.40 or later, ensuring that configurations are secured.
3
What type of vulnerability is CVE-2024-22062?
CVE-2024-22062 is a permissions and access control vulnerability that allows attackers to escalate their privileges.
4
Who is affected by CVE-2024-22062?
CVE-2024-22062 affects users of the ZTE ZXCLOUD IRAI software versions prior to 7.23.40.
5
Can CVE-2024-22062 be exploited remotely?
Yes, CVE-2024-22062 can be exploited remotely if an attacker can access the configuration settings.