5.9

CVE-2022-34746

An insufficient entropy vulnerability caused by the improper use of randomness sources with low entropy for RSA key pair generation was found in Zyxel GS1900 series firmware versions prior to V2.70. This vulnerability could allow an unauthenticated attacker to retrieve a private key by factoring the RSA modulus N in the certificate of the web administration interface.

Data is provided by the National Vulnerability Database (NVD)
ZyxelGs1900-8 Firmware Version < 2.70\(aahh.3\)c0
   ZyxelGs1900-8 Version-
ZyxelGs1900-8hp Firmware Version < 2.70\(aahi.3\)c0
   ZyxelGs1900-8hp Version-
ZyxelGs1900-10hp Firmware Version < 2.70\(aazi.3\)c0
   ZyxelGs1900-10hp Version-
ZyxelGs1900-16 Firmware Version < 2.70\(aahj.3\)c0
   ZyxelGs1900-16 Version-
ZyxelGs1900-24 Firmware Version < 2.70\(aahl.3\)c0
   ZyxelGs1900-24 Version-
ZyxelGs1900-24e Firmware Version < 2.70\(aahk.3\)c0
   ZyxelGs1900-24e Version-
ZyxelGs1900-24ep Firmware Version < 2.70\(abto.3\)c0
   ZyxelGs1900-24ep Version-
ZyxelGs1900-24hpv2 Firmware Version < 2.70\(abtp.3\)c0
   ZyxelGs1900-24hpv2 Version-
ZyxelGs1900-48 Firmware Version < 2.70\(aahn.3\)c0
   ZyxelGs1900-48 Version-
ZyxelGs1900-48hpv2 Firmware Version < 2.70\(abtq.3\)c0
   ZyxelGs1900-48hpv2 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.35% 0.571
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
security@zyxel.com.tw 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-331 Insufficient Entropy

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.