CVE-2015-7255

UnknownEPSS 1.98%

Last modified

CVE-2015-7255 is a vulnerability of currently unknown severity. ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device.. EPSS estimates a 1.98% chance of exploitation in the next 30 days.

Description

ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device.

Metrics

EPSS Probability
1.98%

78.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ZteOx-330p FirmwareAll versions
ZteZxhn H108n FirmwareAll versions
ZteW300v1.0.0s Zrd Tr1 D68 FirmwareAll versions
ZteHg110 FirmwareAll versions
ZteGan9.8t101a-B FirmwareAll versions
ZteMf28g FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-7255?
ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device.
How severe is CVE-2015-7255?
Severity scoring for CVE-2015-7255 is pending analysis. The EPSS model estimates a 1.98% probability of exploitation in the next 30 days.
How do I fix CVE-2015-7255?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-7255?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST