There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permissions to administrator permissions by modifying the configuration.
Solution:
The product does not properly verify that the source of data or communication is valid.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1036204 | vendor advisory |