---
cve: "CVE-2023-41779"
severity: "MEDIUM"
cvss: 4.4
epss: "0.2%"
vendor: "ZTE"
kev: false
exploited: false
published: "2024-01-03 02:15:43"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-21T13:19:29+02:00"
---

# CVE-2023-41779

> 4.4 MEDIUM

## Beschreibung

There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user permission, the physical machine will be crashed.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Hoch | good |
| PR Privilegien | Gering | warn |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1034404>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-41779) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
