ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28230 | ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that low-authority accounts could actually obtain higher operating permissions on key files. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: zte
Published:
Updated: 2024-08-03T03:36:20.000Z
Reserved: 2022-01-11T00:00:00
Link: CVE-2022-23139
No data.
Status : Modified
Published: 2022-05-12T20:15:15.183
Modified: 2024-11-21T06:48:05.017
Link: CVE-2022-23139
No data.
OpenCVE Enrichment
No data.
EUVD