CVE-2020-6874
Severity CVSS v4.0:
Pending analysis
Type:
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
Publication date:
01/09/2020
Last modified:
21/07/2021
Description
A ZTE product is impacted by the cryptographic issues vulnerability. The encryption algorithm is not properly used, so remote attackers could use this vulnerability for account credential enumeration attack or brute-force attack for password guessing. This affects: ZXIPTV, ZXIPTV-WEB-PV5.09.08.04.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Base Score 2.0
5.50
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:zte:zxiptv_firmware:zxiptv-web-pv5.09.08.04:*:*:*:*:*:*:* | ||
cpe:2.3:h:zte:zxiptv:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page