9.1

CVE-2019-12583

Exploit

Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZyxelUag2100 Firmware Version <= 4.18\(aaiz.1\)c0
   ZyxelUag2100 Version-
ZyxelUag4100 Firmware Version <= 4.18\(aatd.1\)c0
   ZyxelUag4100 Version-
ZyxelUag5100 Firmware Version <= 4.18\(aapn.1\)c0
   ZyxelUag5100 Version-
ZyxelUsg110 Firmware Version <= 4.33\(aaph.0\)c0
   ZyxelUsg110 Version-
ZyxelUsg210 Firmware Version <= 4.33\(aapi.0\)c0
   ZyxelUsg210 Version-
ZyxelUsg310 Firmware Version <= 4.33\(aapj.0\)c0
   ZyxelUsg310 Version-
ZyxelUsg1100 Firmware Version <= 4.33\(aapk.0\)c0
   ZyxelUsg1100 Version-
ZyxelUsg1900 Firmware Version <= 4.33\(aapl.0\)c0
   ZyxelUsg1900 Version-
ZyxelUsg2200-vpn Firmware Version <= 4.33\(abae.0\)c0
   ZyxelUsg2200-vpn Version-
ZyxelZywall Vpn100 Firmware Version <= 10.02\(abfv.0\)c0
   ZyxelZywall Vpn100 Version-
ZyxelZywall Vpn300 Firmware Version <= 10.02\(abfc.0\)c0
   ZyxelZywall Vpn300 Version-
ZyxelZywall 110 Firmware Version <= 4.33\(aaaa.0\)c0
   ZyxelZywall 110 Version-
ZyxelZywall 310 Firmware Version <= 4.33\(aaab.0\)c0
   ZyxelZywall 310 Version-
ZyxelZywall 1100 Firmware Version <= 4.33\(aaac.0\)c0
   ZyxelZywall 1100 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 59.06% 0.981
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:N/I:P/A:P
CWE-425 Direct Request ('Forced Browsing')

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.