ID

VAR-201705-4196


TITLE

Converged smart set-top box z84 has any user unauthorized to modify the administrator configuration vulnerability

Trust: 0.6

sources: CNVD: CNVD-2017-04100

DESCRIPTION

The integrated intelligent set-top box z84 is a set-top box product of Shenzhen Zhaoneng Xuntong Technology Co., Ltd. It is a device integrating wireless wifi and smart TV. It is a set-top box widely used by telecommunications in hotels and homes with smart TVs. The z84, a converged intelligent set-top box, has an unauthorized user to modify the administrator configuration vulnerability. Any user on the same network that allows an attacker to use the affected page can override the super administrator's device configuration information.

Trust: 0.6

sources: CNVD: CNVD-2017-04100

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-04100

AFFECTED PRODUCTS

vendor:zhaoneng xuntongmodel:z84scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2017-04100

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-04100
value: LOW

Trust: 0.6

CNVD: CNVD-2017-04100
severity: LOW
baseScore: 3.6
vectorString: AV:N/AC:H/AU:S/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-04100

PATCH

title:Converged smart set-top box z84 has any user unauthorized to modify the administrator configuration vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/91533

Trust: 0.6

sources: CNVD: CNVD-2017-04100

EXTERNAL IDS

db:CNVDid:CNVD-2017-04100

Trust: 0.6

sources: CNVD: CNVD-2017-04100

SOURCES

db:CNVDid:CNVD-2017-04100

LAST UPDATE DATE

2022-05-04T10:04:42.883000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-04100date:2019-05-07T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-04100date:2017-05-15T00:00:00