CVE-2023-25648

There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak folder permission, an attacker with ordinary user privileges could construct a fake DLL to execute command to escalate local privileges.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:zte:zxcloud_irai_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxcloud_irai:-:*:*:*:*:*:*:*

History

19 Dec 2023, 19:25

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 7.8
Summary
  • (es) Existe una vulnerabilidad de permiso de carpeta débil en el producto ZXCLOUD iRAI de ZTE. Debido a un permiso de carpeta débil, un atacante con privilegios de usuario normales podría construir una DLL falsa para ejecutar un comando para escalar los privilegios locales.
First Time Zte zxcloud Irai Firmware
Zte
Zte zxcloud Irai
CPE cpe:2.3:o:zte:zxcloud_irai_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:zte:zxcloud_irai:-:*:*:*:*:*:*:*
References () https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1032584 - () https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1032584 - Vendor Advisory

14 Dec 2023, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-14 07:15

Updated : 2023-12-19 19:25


NVD link : CVE-2023-25648

Mitre link : CVE-2023-25648

CVE.ORG link : CVE-2023-25648


JSON object : View

Products Affected

zte

  • zxcloud_irai
  • zxcloud_irai_firmware
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource