SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-7364

All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability.

CRITICAL 9.8EPSS 10.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 10.3%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.

Description

All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper access control to devcomm process, an unauthorized remote attacker can exploit this vulnerability to execute arbitrary code with root privileges.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
10.29% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
zte/zxin10
Source
psirt@zte.com.cn

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.