Home
MEDIUM: 5.5 CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:NDefault status
unaffected
ZXCLOUD-iRAI-ClientV7.2X
affected
Description
There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execute arbitrary code locally and escalate privileges.
Problem types
CWE-427 Uncontrolled Search Path Element
Product status
ZXCLOUD-iRAI-ClientV7.2X
Credits
Runzi Zhao, Feng Ye and Ziwei Wang
References
support.zte.com.cn/...ui/bulletin/detail/3126272076755775573