Hardcoded Certificate Vulnerability in Zyxel CloudCNM SecuManager
CVE-2020-15326
5.3MEDIUM
Summary
In Zyxel CloudCNM SecuManager versions 3.1.0 and 3.1.1, a vulnerability exists due to a hardcoded certificate for Ejabberd in ejabberd.pem. This could potentially allow attackers to exploit the certificate and gain unauthorized access to sensitive communications. Organizations using the affected versions are advised to assess their security posture and consider updating to mitigate any risks associated with the use of hardcoded credentials.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved