Zyxel Cloudcnm Secumanager vulnerabilities
35 known vulnerabilities affecting zyxel/cloudcnm_secumanager.
Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH5MEDIUM23
Vulnerabilities
Page 1 of 2
CVE-2020-15347P2CRITICALCVSS 9.8v3.1.0v3.1.12022-09-29
CVE-2020-15347 [CRITICAL] CWE-522 CVE-2020-15347: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.
nvd
CVE-2020-15323P2CRITICALCVSS 9.8v3.1.0v3.1.12020-06-29
CVE-2020-15323 [CRITICAL] CWE-798 CVE-2020-15323: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account defa
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.
nvd
CVE-2020-15320P2CRITICALCVSS 9.8v3.1.0v3.1.12020-06-29
CVE-2020-15320 [CRITICAL] CWE-798 CVE-2020-15320: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.
nvd
CVE-2020-15321P2CRITICALCVSS 9.8v3.1.0v3.1.12020-06-29
CVE-2020-15321 [CRITICAL] CWE-798 CVE-2020-15321: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.
nvd
CVE-2020-15322P3CRITICALCVSS 9.8v3.1.0v3.1.12020-06-29
CVE-2020-15322 [CRITICAL] CWE-798 CVE-2020-15322: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debia
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.
nvd
CVE-2020-15341P3HIGHCVSS 7.5v3.1.0v3.1.12022-09-29
CVE-2020-15341 [HIGH] CWE-522 CVE-2020-15341: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated update_all_realm_license API.
nvd
CVE-2020-15336P3HIGHCVSS 7.5v3.1.0v3.1.12020-06-26
CVE-2020-15336 [HIGH] CWE-306 CVE-2020-15336: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /cnr requests.
nvd
CVE-2020-15335P3HIGHCVSS 7.5v3.1.0v3.1.12020-06-26
CVE-2020-15335 [HIGH] CWE-306 CVE-2020-15335: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has no authentication for /registerCpe requests.
nvd
CVE-2020-15331P3CRITICALCVSS 9.8v3.1.0v3.1.12022-09-29
CVE-2020-15331 [CRITICAL] CWE-311 CVE-2020-15331: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/defaul
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.
nvd
CVE-2020-15332P3CRITICALCVSS 9.8v3.1.0v3.1.12022-09-29
CVE-2020-15332 [CRITICAL] CWE-312 CVE-2020-15332: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.
nvd
CVE-2020-15327P3HIGHCVSS 7.5v3.1.0v3.1.12022-09-29
CVE-2020-15327 [HIGH] CWE-798 CVE-2020-15327: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.
nvd
CVE-2020-15340P3HIGHCVSS 7.5v3.1.0v3.1.12022-09-29
CVE-2020-15340 [HIGH] CWE-311 CVE-2020-15340: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded opt/axess/AXAssets/default_axess/axess/TR69/Handlers/turbolink/sshkeys/id_rsa SSH key.
nvd
CVE-2020-15343P4MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15343 [MEDIUM] CWE-311 CVE-2020-15343: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user_key API.
nvd
CVE-2020-15345P4MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15345 [MEDIUM] CWE-311 CVE-2020-15345: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_instances_for_update API.
nvd
CVE-2020-15344P4MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15344 [MEDIUM] CWE-311 CVE-2020-15344: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_get_user_id_and_key API.
nvd
CVE-2020-15342P4MEDIUMCVSS 5.3v3.1.0v3.1.12022-09-29
CVE-2020-15342 [MEDIUM] CWE-311 CVE-2020-15342: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has an unauthenticated zy_install_user API.
nvd
CVE-2020-15312P4MEDIUMCVSS 5.9v3.1.0v3.1.12020-06-29
CVE-2020-15312 [MEDIUM] CWE-798 CVE-2020-15312: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded DSA SSH key for the root account.
nvd
CVE-2020-15314P4MEDIUMCVSS 5.9v3.1.0v3.1.12020-06-29
CVE-2020-15314 [MEDIUM] CWE-798 CVE-2020-15314: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded RSA SSH key for the root account.
nvd
CVE-2020-15313P4MEDIUMCVSS 5.9v3.1.0v3.1.12020-06-29
CVE-2020-15313 [MEDIUM] CWE-798 CVE-2020-15313: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account.
nvd
CVE-2020-15316P4MEDIUMCVSS 5.9v3.1.0v3.1.12020-06-29
CVE-2020-15316 [MEDIUM] CWE-798 CVE-2020-15316: Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded ECDSA SSH key for the root account within the /opt/axess chroot directory tree.
nvd
1 / 2Next →