CVE-2020-15333SQL Injection in Zyxel Cloudcnm Secumanager

CWE-89SQL Injection3 documents3 sources
Severity
5.3MEDIUMNVD
EPSS
0.3%
top 45.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 29
Latest updateSep 30

Description

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Users_users" requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

NVDzyxel/cloudcnm_secumanager3.1.0, 3.1.1+1

🔴Vulnerability Details

2
GHSA
GHSA-c56x-jj48-c26x: Zyxel CloudCNM SecuManager 32022-09-30
CVEList
CVE-2020-15333: Zyxel CloudCNM SecuManager 32020-06-26
CVE-2020-15333 — SQL Injection in Zyxel | cvebase