Java RMI Service Vulnerability in ZTE ZXIPTV-EPG
CVE-2017-10934

9.8CRITICAL

Key Information:

Vendor

Zte

Vendor
CVE Published:
25 July 2018

What is CVE-2017-10934?

The ZTE ZXIPTV-EPG product, in all versions prior to V5.09.02.02T4, is susceptible to vulnerabilities stemming from its Java RMI service. This service utilizes the Apache Commons Collections library, which can lead to Java deserialization issues. An unauthenticated remote attacker may exploit this vulnerability by sending a crafted RMI request, potentially allowing for the execution of arbitrary code on the target system. This poses significant security risks, warranting immediate attention from users of the affected product.

Affected Version(s)

ZXIPTV-EPG All versions prior to V5.09.02.02T4

References

EPSS Score

9% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.