CVE-2018-7363 Vulnerability Details
/
/
/
CVE-2018-7363 Metadata Quick Info
CVE Published: 16/11/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018
Source: zte |
Vendor: ZTE |
Product: ZXHN F670
Status : PUBLISHED
CVE-2018-7363 Description
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper authorization vulnerability. Since appviahttp service has no authorization delay, an attacker can be allowed to brute force account credentials.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: Improper Authorization
Source: ZTE
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).