9.1

CVE-2019-12583

Exploit
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zyxel ≫ Uag2100 Firmware Version <= 4.18\(aaiz.1\)c0
   Zyxel ≫ Uag2100 Version -
Zyxel ≫ Uag4100 Firmware Version <= 4.18\(aatd.1\)c0
   Zyxel ≫ Uag4100 Version -
Zyxel ≫ Uag5100 Firmware Version <= 4.18\(aapn.1\)c0
   Zyxel ≫ Uag5100 Version -
Zyxel ≫ Usg110 Firmware Version <= 4.33\(aaph.0\)c0
   Zyxel ≫ Usg110 Version -
Zyxel ≫ Usg210 Firmware Version <= 4.33\(aapi.0\)c0
   Zyxel ≫ Usg210 Version -
Zyxel ≫ Usg310 Firmware Version <= 4.33\(aapj.0\)c0
   Zyxel ≫ Usg310 Version -
Zyxel ≫ Usg1100 Firmware Version <= 4.33\(aapk.0\)c0
   Zyxel ≫ Usg1100 Version -
Zyxel ≫ Usg1900 Firmware Version <= 4.33\(aapl.0\)c0
   Zyxel ≫ Usg1900 Version -
Zyxel ≫ Usg2200-vpn Firmware Version <= 4.33\(abae.0\)c0
   Zyxel ≫ Usg2200-vpn Version -
Zyxel ≫ Zywall Vpn100 Firmware Version <= 10.02\(abfv.0\)c0
   Zyxel ≫ Zywall Vpn100 Version -
Zyxel ≫ Zywall Vpn300 Firmware Version <= 10.02\(abfc.0\)c0
   Zyxel ≫ Zywall Vpn300 Version -
Zyxel ≫ Zywall 110 Firmware Version <= 4.33\(aaaa.0\)c0
   Zyxel ≫ Zywall 110 Version -
Zyxel ≫ Zywall 310 Firmware Version <= 4.33\(aaab.0\)c0
   Zyxel ≫ Zywall 310 Version -
Zyxel ≫ Zywall 1100 Firmware Version <= 4.33\(aaac.0\)c0
   Zyxel ≫ Zywall 1100 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 43.93% 0.986
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:N/I:P/A:P
CWE-425 Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

https://n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generator-xss/
Third Party Advisory
Exploit
https://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtml
Patch
Vendor Advisory