ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devices connecting over the internet . If the set of keys are leaked or cracked, the user session informations using the keys may be leaked.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-19662 ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devices connecting over the internet . If the set of keys are leaked or cracked, the user session informations using the keys may be leaked.
Fixes

Solution

V5.20.20


Workaround

No workaround given by the vendor.

History

Tue, 28 Jan 2025 16:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:h:zte:zxun-epdg:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxun-epdg_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:zte:zxun-epdg:*:*:*:*:*:*:*:*
Vendors & Products Zte zxun-epdg Firmware

Mon, 27 Jan 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Zte
Zte zxun-epdg
Zte zxun-epdg Firmware
Weaknesses CWE-665
CPEs cpe:2.3:h:zte:zxun-epdg:-:*:*:*:*:*:*:*
cpe:2.3:o:zte:zxun-epdg_firmware:*:*:*:*:*:*:*:*
Vendors & Products Zte
Zte zxun-epdg
Zte zxun-epdg Firmware

cve-icon MITRE

Status: PUBLISHED

Assigner: zte

Published:

Updated: 2024-08-01T22:35:34.708Z

Reserved: 2024-01-05T01:51:09.680Z

Link: CVE-2024-22064

cve-icon Vulnrichment

Updated: 2024-08-01T22:35:34.708Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-14T14:56:40.160

Modified: 2025-01-28T16:12:31.863

Link: CVE-2024-22064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.