CVE-2019-15017
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
09/10/2019
Last modified:
04/02/2023
Description
The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker to authenticate to the service using hardcoded credentials.
Impact
Base Score 3.x
8.40
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zingbox:inspector:*:*:*:*:*:*:*:* | 1.294 (including) |
To consult the complete list of CPE names with products and versions, see this page



