Improper Authentication in XMM 7560 Modem - CVE-2022-27874

 

Improper Authentication in XMM 7560 Modem - CVE-2022-27874

Published: November 11, 2022


Vulnerability identifier: #VU69250
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:P/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-27874
CWE-ID: CWE-287
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. An administrator with physical access can bypass authentication process and gain elevated privileges on the system.


Affected software

XMM 7560 Modem

How to mitigate CVE-2022-27874

Install updates from vendor's website.

XMM 7560 Modem - update to M2_7560_R_01.2146.00

External References

Related Security Bulletins