Description
backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows remote attackers to obtain arbitrary user passwords via the sessionKey parameter in a getConfig action to backupsettings.conf.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T13:18:48.376Z
Reserved: 2014-10-20T00:00:00.000Z
Link: CVE-2014-8357
No data.
Status : Modified
Published: 2017-10-17T16:29:00.207
Modified: 2026-05-13T00:24:29.033
Link: CVE-2014-8357
No data.
OpenCVE Enrichment
No data.
Weaknesses