CVE-2022-23144
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD
Description
There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission control, attackers could use this vulnerability to delete the default application type, which affects normal use of system.
Affected (15)
Products: Zte: Zxa10 B76hv3 Firmware, Zxa10 B766v2 Firmware, Zxa10 B800v2 Firmware, Zxa10 B860av2.1 Firmware, Zxa10 B860h Firmware, Zxa10 B866v2 H Firmware, Zxa10 B866v5 W10 Firmware, Zxa10 B960gv1 Firmware, Zxa10 B710c A12 Firmware, Zxa10 B710s2 A19 Firmware, Zxa10 B836ct A15 Firmware, Zxa10 S100v Firmware, Zxa10 S200a Firmware, Zxa10 S200t Firmware, Zxa10 B700v7 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 B76hv3 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 B766v2 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 B800v2 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 B860av2.1 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 B860h | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 B866v2 H | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 B866v5 W10 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 B960gv1 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 B710c A12 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 B710s2 A19 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 B836ct A15 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 S100v | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 S200a | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 S200t | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.01.02.01 |
| Running on/with | Platform Versions |
|---|---|
Zte Zxa10 B700v7 | All versions |
References (2)
Source: psirt@zte.com.cn
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.