CVE-2020-15321 โ€” Hard-coded Credentials in Zyxel Cloudcnm Secumanager

Severity
9.8CRITICALNVD
EPSS
0.5%
top 33.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 29
Latest updateMay 24

Description

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

โ–ถNVDzyxel/cloudcnm_secumanager3.1.0, 3.1.1+1

๐Ÿ”ดVulnerability Details

2
GHSA
GHSA-7vjf-h2h5-h642: Zyxel CloudCNM SecuManager 3โ†—2022-05-24
โ–ถ
CVEList
CVE-2020-15321: Zyxel CloudCNM SecuManager 3โ†—2020-06-29
โ–ถ
CVE-2020-15321 โ€” Hard-coded Credentials in Zyxel | cvebase