Zyxel Cloudcnm Secumanager vulnerabilities

35 known vulnerabilities affecting zyxel/cloudcnm_secumanager.

Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH5MEDIUM23

Vulnerabilities

Page 1 of 2
CVE-2020-15331CRITICALCVSS 9.8v3.1.0v3.1.12022-09-29
CVE-2020-15331 [CRITICAL] CWE-311 CVE-2020-15331: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/defaul Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.
nvd
CVE-2020-15332CRITICALCVSS 9.8v3.1.0v3.1.12022-09-29
CVE-2020-15332 [CRITICAL] CWE-312 CVE-2020-15332: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
nvd
CVE-2020-15347CRITICALCVSS 9.8v3.1.0v3.1.12022-09-29
CVE-2020-15347 [CRITICAL] CWE-522 CVE-2020-15347: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.
nvd
CVE-2020-15341HIGHCVSS 7.5v3.1.0v3.1.12022-09-29
CVE-2020-15341 [HIGH] CWE-522 CVE-2020-15341: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.
nvd
CVE-2020-15327HIGHCVSS 7.5v3.1.0v3.1.12022-09-29
CVE-2020-15327 [HIGH] CWE-798 CVE-2020-15327: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.
nvd
CVE-2020-15340HIGHCVSS 7.5v3.1.0v3.1.12022-09-29
CVE-2020-15340 [HIGH] CWE-311 CVE-2020-15340: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key.
nvd
CVE-2020-15345MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15345 [MEDIUM] CWE-311 CVE-2020-15345: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API.
nvd
CVE-2020-15339MEDIUMCVSS 6.1v3.1.0v3.1.12022-09-29
CVE-2020-15339 [MEDIUM] CWE-79 CVE-2020-15339: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_ Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handle_campaign_script_link?script_name= XSS.
nvd
CVE-2020-15329MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15329 [MEDIUM] CWE-732 CVE-2020-15329: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak Data.fs permissions.
nvd
CVE-2020-15326MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15326 [MEDIUM] CWE-798 CVE-2020-15326: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded certificate for Ejabberd in ejabberd.pem.
nvd
CVE-2020-15325MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15325 [MEDIUM] CWE-312 CVE-2020-15325: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded Erlang cookie for ejabberd replication.
nvd
CVE-2020-15344MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15344 [MEDIUM] CWE-311 CVE-2020-15344: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.
nvd
CVE-2020-15330MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15330 [MEDIUM] CWE-311 CVE-2020-15330: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded APP_KEY in /opt/axess/etc/default/axess.
nvd
CVE-2020-15328MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15328 [MEDIUM] CWE-732 CVE-2020-15328: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/var/blobstorage/ permissions.
nvd
CVE-2020-15342MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15342 [MEDIUM] CWE-311 CVE-2020-15342: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.
nvd
CVE-2020-15333MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15333 [MEDIUM] CWE-89 CVE-2020-15333: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows attackers to discover accounts via MySQL "select * from Administrator_users" and "select * from Users_users" requests.
nvd
CVE-2020-15334MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15334 [MEDIUM] CVE-2020-15334: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows escape-sequence injection into the /var/log/axxmpp.log file.
nvd
CVE-2020-15346MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15346 [MEDIUM] CWE-311 CVE-2020-15346: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a /live/GLOBALS API with the CLOUDCNM key.
nvd
CVE-2020-15343MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15343 [MEDIUM] CWE-311 CVE-2020-15343: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API. Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.
nvd
CVE-2020-15338MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15338 [MEDIUM] CWE-862 CVE-2020-15338: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Str Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests.
nvd