cvelist/2019/3xxx/CVE-2019-3413.json
2019-06-11 20:00:51 +00:00

82 lines
2.6 KiB
JSON

{
"CVE_data_meta": {
"ASSIGNER": "psirt@zte.com.cn",
"ID": "CVE-2019-3413",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "NetNumen DAP",
"version": {
"version_data": [
{
"affected": "<=",
"version_value": "All versions up to NetNumen DAP V20.18.40.R7.B1"
}
]
}
}
]
},
"vendor_name": "ZTE"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "All versions up to V20.18.40.R7.B1of ZTE NetNumen DAP product have an XSS vulnerability. Due to the lack of correct validation of client data in WEB applications, which results in users being hijacked."
}
]
},
"impact": {
"cvss": {
"attackComplexity": "LOW",
"attackVector": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "Medium",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.0"
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Command Injection"
}
]
}
]
},
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"name": "http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1010797",
"url": "http://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1010797"
}
]
},
"source": {
"discovery": "UNKNOWN"
}
}