6.5
CVE-2022-0910
- EPSS 0.15%
- Published 24.05.2022 03:15:09
- Last modified 21.11.2024 06:39:39
- Source security@zyxel.com.tw
- Teams watchlist Login
- Open Login
A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN series firmware versions 4.32 through 5.21, that could allow an authenticated attacker to bypass the second authentication phase to connect the IPsec VPN server even though the two-factor authentication (2FA) was enabled.
Data is provided by the National Vulnerability Database (NVD)
Zyxel ≫ Vpn100 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Vpn1000 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Vpn300 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Vpn50 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Atp100 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Atp100w Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Atp200 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Atp500 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Atp700 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Atp800 Firmware Version >= 4.32 <= 5.21
Zyxel ≫ Usg 110 Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg 1100 Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg 1900 Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg 20w Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg 20w-vpn Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg 2200-vpn Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg 310 Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg 40 Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg 40w Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg 60 Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg 60w Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg Flex 100 Firmware Version >= 4.50 <= 5.21
Zyxel ≫ Usg Flex 100w Firmware Version >= 4.50 <= 5.21
Zyxel ≫ Usg Flex 200 Firmware Version >= 4.50 <= 5.21
Zyxel ≫ Usg Flex 500 Firmware Version >= 4.50 <= 5.21
Zyxel ≫ Usg Flex 700 Firmware Version >= 4.50 <= 5.21
Zyxel ≫ Usg200 Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg20 Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg210 Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg2200 Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg300 Firmware Version >= 4.32 <= 4.71
Zyxel ≫ Usg310 Firmware Version >= 4.32 <= 4.71
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.15% | 0.364 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
security@zyxel.com.tw | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.