9.8

CVE-2022-0342

An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.

Data is provided by the National Vulnerability Database (NVD)
ZyxelUsg40 Firmware Version >= 4.20 < 4.71
   ZyxelUsg40 Version-
ZyxelUsg40w Firmware Version >= 4.20 < 4.71
   ZyxelUsg40w Version-
ZyxelUsg60 Firmware Version >= 4.20 < 4.71
   ZyxelUsg60 Version-
ZyxelUsg60w Firmware Version >= 4.20 < 4.71
   ZyxelUsg60w Version-
ZyxelZywall 110 Firmware Version >= 4.20 < 4.71
   ZyxelZywall 110 Version-
ZyxelZywall 310 Firmware Version >= 4.20 < 4.71
   ZyxelZywall 310 Version-
ZyxelZywall 1100 Firmware Version >= 4.20 < 4.71
   ZyxelZywall 1100 Version-
ZyxelUsg Flex 100 Firmware Version >= 4.50 <= 5.20
   ZyxelUsg Flex 100 Version-
ZyxelUsg Flex 200 Firmware Version >= 4.50 <= 5.20
   ZyxelUsg Flex 200 Version-
ZyxelUsg Flex 500 Firmware Version >= 4.50 <= 5.20
   ZyxelUsg Flex 500 Version-
ZyxelUsg Flex 100w Firmware Version >= 4.50 <= 5.20
   ZyxelUsg Flex 100w Version-
ZyxelUsg Flex 700 Firmware Version >= 4.50 <= 5.20
   ZyxelUsg Flex 700 Version-
ZyxelAtp100 Firmware Version >= 4.32 <= 5.20
   ZyxelAtp100 Version-
ZyxelAtp100w Firmware Version >= 4.32 <= 5.20
   ZyxelAtp100w Version-
ZyxelAtp200 Firmware Version >= 4.32 <= 5.20
   ZyxelAtp200 Version-
ZyxelAtp500 Firmware Version >= 4.32 <= 5.20
   ZyxelAtp500 Version-
ZyxelAtp700 Firmware Version >= 4.32 <= 5.20
   ZyxelAtp700 Version-
ZyxelAtp800 Firmware Version >= 4.32 <= 5.20
   ZyxelAtp800 Version-
ZyxelVpn50 Firmware Version >= 4.30 < 5.21
   ZyxelVpn50 Version-
ZyxelVpn100 Firmware Version >= 4.30 < 5.21
   ZyxelVpn100 Version-
ZyxelVpn300 Firmware Version >= 4.30 < 5.21
   ZyxelVpn300 Version-
ZyxelVpn1000 Firmware Version >= 4.30 < 5.21
   ZyxelVpn1000 Version-
ZyxelNsg300 Firmware Version >= 1.20 < 1.33
   ZyxelNsg300 Version-
ZyxelNsg300 Firmware Version1.33 Update-
   ZyxelNsg300 Version-
ZyxelNsg300 Firmware Version1.33 Updatep4
   ZyxelNsg300 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 92.29% 0.997
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
security@zyxel.com.tw 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.