6.5
CVE-2021-35036
- EPSS 0.19%
- Published 01.03.2022 07:15:06
- Last modified 21.11.2024 06:11:43
- Source security@zyxel.com.tw
- Teams watchlist Login
- Open Login
A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated attacker to obtain sensitive information from the configuration file.
Data is provided by the National Vulnerability Database (NVD)
Zyxel ≫ Ax7501-b0 Firmware Version < 5.17\(abpc.2\)c0
Zyxel ≫ Dx3301-t0 Firmware Version < 5.50\(abvy.3\)c0
Zyxel ≫ Dx5401-b0 Firmware Version < 5.17\(abyo.2\)c0
Zyxel ≫ Emg3525-t50b Firmware Version < 5.50\(abpm.7\)c0
Zyxel ≫ Emg5523-t50b Firmware Version < 5.50\(abpm.7\)c0
Zyxel ≫ Emg5723-t50k Firmware Version < 5.50\(abom.8\)c0
Zyxel ≫ Ep240p Firmware Version < 5.40\(abvh.0\)c0a03
Zyxel ≫ Ex5401-b0 Firmware Version < 5.17\(abyo.2\)c0
Zyxel ≫ Ex5501-b0 Firmware Version < 5.17\(abry.3\)c0
Zyxel ≫ Lte3301-plus Firmware Version < 1.00\(abqu.6\)c0
Zyxel ≫ Lte5388-m804 Firmware Version < 1.00\(abra.6\)c0
Zyxel ≫ Lte5388-s905 Firmware Version < 1.00\(abvi.6\)c0
Zyxel ≫ Lte5398-m904 Firmware Version < 1.00\(abqv.2\)c0
Zyxel ≫ Lte7240-m403 Firmware Version < 2.00\(abmg.6\)c0
Zyxel ≫ Lte7461-m602 Firmware Version < 2.00\(abqn.6\)c0
Zyxel ≫ Lte7480-m804 Firmware Version < 1.00\(abra.6\)c0
Zyxel ≫ Lte7480-s905 Firmware Version < 2.00\(abqt.6\)c0
Zyxel ≫ Lte7485-s905 Firmware Version < 1.00\(abvn.6\)c0
Zyxel ≫ Lte7490-m804 Firmware Version < v1.00\(abqy.5\)c0
Zyxel ≫ Nr5101 Firmware Version < 1.00\(abvc.6\)c0
Zyxel ≫ Nr7101 Firmware Version < 1.00\(abuv.7\)c0
Zyxel ≫ Nr7102 Firmware Version < 1.00\(abyd.2\)c0
Zyxel ≫ Pm7300-t0 Firmware Version < 5.42\(acbc.1\)c0
Zyxel ≫ Pmg5317-t20b Firmware Version < 5.40\(abki.4\)c0
Zyxel ≫ Pmg5617-t20b2 Firmware Version < 5.41\(acbb.1\)c0
Zyxel ≫ Pmg5617ga Firmware Version < 5.40\(abna.2\)c0
Zyxel ≫ Pmg5622ga Firmware Version < 5.40\(abnb.2\)c0
Zyxel ≫ Vmg3625-t50b Firmware Version < 5.50\(abtl.0\)b2r
Zyxel ≫ Vmg3927-t50k Firmware Version < 5.50\(abom.8\)c0
Zyxel ≫ Vmg8623-t50b Firmware Version < 5.50\(abpm.7\)c0
Zyxel ≫ Vmg8825-t50k Firmware Version < 5.50\(abom.8\)c0
Zyxel ≫ Vmg3625-t50b Firmware SwEditioncentral_america Version < 5.50\(accr.0\)b4
Zyxel ≫ Vmg3625-t50b Firmware SwEditionemea Version < 5.50\(abpm.7\)c0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.19% | 0.413 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:P/I:N/A:N
|
security@zyxel.com.tw | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.