6.5
CVE-2023-22918
- EPSS 0.21%
- Published 24.04.2023 18:15:09
- Last modified 21.11.2024 07:45:38
- Source security@zyxel.com.tw
- Teams watchlist Login
- Open Login
A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmware version 6.50(ABTG.2) and earlier versions, WAC500 firmware version 6.50(ABVS.0) and earlier versions, and WAX510D firmware version 6.50(ABTF.2) and earlier versions, which could allow a remote authenticated attacker to retrieve encrypted information of the administrator on an affected device.
Data is provided by the National Vulnerability Database (NVD)
Zyxel ≫ Atp200 Firmware Version >= 4.32 < 5.36
Zyxel ≫ Atp100 Firmware Version >= 4.32 < 5.36
Zyxel ≫ Atp700 Firmware Version >= 4.32 < 5.36
Zyxel ≫ Atp500 Firmware Version >= 4.32 < 5.36
Zyxel ≫ Atp100w Firmware Version >= 4.32 < 5.36
Zyxel ≫ Atp800 Firmware Version >= 4.32 < 5.36
Zyxel ≫ Usg Flex 100 Firmware Version >= 4.50 < 5.36
Zyxel ≫ Usg Flex 50 Firmware Version >= 4.50 < 5.36
Zyxel ≫ Usg Flex 200 Firmware Version >= 4.50 < 5.36
Zyxel ≫ Usg Flex 500 Firmware Version >= 4.50 < 5.36
Zyxel ≫ Usg Flex 700 Firmware Version >= 4.50 < 5.36
Zyxel ≫ Usg Flex 100w Firmware Version >= 4.50 < 5.36
Zyxel ≫ Usg 20w-vpn Firmware Version >= 4.16 < 5.36
Zyxel ≫ Usg Flex 50w Firmware Version >= 4.16 < 5.36
Zyxel ≫ Usg20-vpn Firmware Version >= 4.30 < 5.36
Zyxel ≫ Vpn100 Firmware Version >= 4.30 < 5.36
Zyxel ≫ Vpn1000 Firmware Version >= 4.30 < 5.36
Zyxel ≫ Vpn300 Firmware Version >= 4.30 < 5.36
Zyxel ≫ Vpn50 Firmware Version >= 4.30 < 5.36
Zyxel ≫ Nap203 Firmware Version <= 6.28\(abfa.0\)
Zyxel ≫ Nap303 Firmware Version <= 6.28\(abex.0\)
Zyxel ≫ Nap353 Firmware Version <= 6.28\(abey.0\)
Zyxel ≫ Nwa110ax Firmware Version <= 6.50\(abtg.2\)
Zyxel ≫ Nwa1123-ac Hd Firmware Version <= 6.25\(abin.9\)
Zyxel ≫ Nwa1123-ac-pro Firmware Version <= 6.28\(abhd.0\)
Zyxel ≫ Nwa1123acv3 Firmware Version <= 6.50\(abvt.0\)
Zyxel ≫ Nwa210ax Firmware Version <= 6.50\(abtd.2\)
Zyxel ≫ Nwa220ax-6e Firmware Version <= 6.50\(acco.2\)
Zyxel ≫ Nwa50ax Firmware Version <= 6.55\(acge.1\)
Zyxel ≫ Nwa50ax-pro Firmware Version <= 6.50\(acge.0\)
Zyxel ≫ Nwa5123-ac Hd Firmware Version <= 6.25\(abim.9\)
Zyxel ≫ Nwa55axe Firmware Version <= 6.29\(abzl.1\)
Zyxel ≫ Nwa90ax Firmware Version <= 6.29\(accv.1\)
Zyxel ≫ Nwa90ax-pro Firmware Version <= 6.50\(acgf.0\)
Zyxel ≫ Wac500 Firmware Version <= 6.50\(abvs.0\)
Zyxel ≫ Wac500h Firmware Version <= 6.50\(abwa.0\)
Zyxel ≫ Wac5302d-sv2 Firmware Version <= 6.25\(abvz.9\)
Zyxel ≫ Wac6103d-i Firmware Version <= 6.28\(aaxh.0\)
Zyxel ≫ Wac6303d-s Firmware Version <= 6.25\(abgl.9\)
Zyxel ≫ Wac6502d-e Firmware Version <= 6.28\(aasd.0\)
Zyxel ≫ Wac6502d-s Firmware Version <= 6.28\(aase.0\)
Zyxel ≫ Wac6503d-s Firmware Version <= 6.28\(aasf.0\)
Zyxel ≫ Wac6552d-s Firmware Version <= 6.28\(abio.0\)
Zyxel ≫ Wac6553d-e Firmware Version <= 6.28\(aasg.0\)
Zyxel ≫ Wax510d Firmware Version <= 6.50\(abtf.2\)
Zyxel ≫ Wax610d Firmware Version <= 6.50\(abte.2\)
Zyxel ≫ Wax620d-6e Firmware Version <= 6.50\(accn.2\)
Zyxel ≫ Wax630s Firmware Version <= 6.50\(abzd.2\)
Zyxel ≫ Wax640s-6e Firmware Version <= 6.50\(accm.2\)
Zyxel ≫ Wax650s Firmware Version <= 6.50\(abrm.2\)
Zyxel ≫ Wax655e Firmware Version <= 6.50\(acdo.2\)
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.21% | 0.402 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
security@zyxel.com.tw | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor
The product does not properly prevent a person's private, personal information from being accessed by actors who either (1) are not explicitly authorized to access the information or (2) do not have the implicit consent of the person about whom the information is collected.