Vulnerability Details CVE-2019-15017
The SSH service is enabled on the Zingbox Inspector versions 1.294 and earlier, exposing SSH to the local network. When combined with PAN-SA-2019-0027, this can allow an attacker to authenticate to the service using hardcoded credentials.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 12.9%
CVSS Severity
CVSS v3 Score 8.4
CVSS v2 Score 7.2
Products affected by CVE-2019-15017
-
cpe:2.3:a:zingbox:inspector:-
-
cpe:2.3:a:zingbox:inspector:1.280
-
cpe:2.3:a:zingbox:inspector:1.281
-
cpe:2.3:a:zingbox:inspector:1.286
-
cpe:2.3:a:zingbox:inspector:1.287
-
cpe:2.3:a:zingbox:inspector:1.288
-
cpe:2.3:a:zingbox:inspector:1.293
-
cpe:2.3:a:zingbox:inspector:1.294