All versions up to V3.03.10.B23P2 of ZTE ZXR10 8905E product are impacted by TCP Initial Sequence Number (ISN) reuse vulnerability, which can generate easily predictable ISN, and allows remote attackers to spoof connections.
References
Link | Resource |
---|---|
http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1009783 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2018-11-01 06:29
Updated : 2019-10-09 16:42
NVD link : CVE-2018-7356
Mitre link : CVE-2018-7356
JSON object : View
CWE
CWE-294
Authentication Bypass by Capture-replay
Products Affected
zte
- zxr10_8905e
- zxr10_8905e_firmware