CVE-2019-3431

CRITICAL

ZTE Zxcloud Goldendata Vap - Insufficiently Protected Credentials

Title source: rule
STIX 2.1

Description

All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have encryption problems vulnerability. Attackers could sniff unencrypted account and password through the network for front-end system access.

Scores

CVSS v3 9.8
EPSS 0.0007
EPSS Percentile 21.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522 CWE-311
Status published
Products (1)
zte/zxcloud_goldendata_vap < zxivs-vap-portal-xzgav4.01.01.02
Published Dec 23, 2019
Tracked Since Feb 18, 2026