Resource Management Error Vulnerability in a ZTE Product

Original release date:   April 28, 2020

 

CVE ID

CVE-2020-6867

 

CVSS 3.0 Base Score

5.5 Medium AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

 

Description

ZTE's SDON controller is impacted by the resource management error vulnerability. When RPC is frequently called by other applications in the case of mass traffic data in the system, it will result in no response for a long time and memory overflow risk.

 

Affected Products and Fixes

Product Name

Affected Version

Resolved Version

ZENIC ONE R22b

V16.19.10P02SP002

V16.19.10P02SP005

V16.19.10P02SP007B005

 

Update Records

April 28, 2020, initial.

 

Supporting team contacts

1. ZTE GCSC hotline:

0755-26770800

800-830-1118

400-830-1118

2. Product forum at ZTE Support website.

 

ZTE PSIRT

If you need to report security vulnerabilities related to ZTE products, or get ZTE product security incident response service and vulnerability information, please contact ZTE PSIRT: psirt@zte.com.cn, PGP key ID: FF095577.

[Close]