CVE-2020-15322 β€” Hard-coded Credentials in Zyxel Cloudcnm Secumanager

Severity
9.8CRITICALNVD
EPSS
0.5%
top 33.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 29
Latest updateMay 24

Description

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

β–ΆNVDzyxel/cloudcnm_secumanager3.1.0, 3.1.1+1

πŸ”΄Vulnerability Details

2
GHSA
GHSA-qxqc-wrvx-gr3v: Zyxel CloudCNM SecuManager 3β†—2022-05-24
β–Ά
CVEList
CVE-2020-15322: Zyxel CloudCNM SecuManager 3β†—2020-06-29
β–Ά
CVE-2020-15322 β€” Hard-coded Credentials in Zyxel | cvebase