5.5

CVE-2023-5797

An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, NWA50AX firmware version 6.29(ABYW.2), WAC500 firmware version 6.65(ABVS.1), WAX300H firmware version 6.60(ACHF.1), and WBE660S firmware version 6.65(ACGG.1), could allow an authenticated local attacker to access the administrator’s logs on an affected device.

Data is provided by the National Vulnerability Database (NVD)
ZyxelZld Version >= 4.32 <= 5.37
   ZyxelAtp100 Version-
   ZyxelAtp100w Version-
   ZyxelAtp200 Version-
   ZyxelAtp500 Version-
   ZyxelAtp700 Version-
   ZyxelAtp800 Version-
ZyxelZld Version >= 4.50 <= 5.37
   ZyxelUsg Flex 100 Version-
   ZyxelUsg Flex 100w Version-
   ZyxelUsg Flex 200 Version-
   ZyxelUsg Flex 50 Version-
   ZyxelUsg Flex 500 Version-
   ZyxelUsg Flex 50w Version-
   ZyxelUsg Flex 700 Version-
ZyxelZld Version >= 4.16 <= 5.37
   ZyxelUsg 20w-vpn Version-
   ZyxelVpn50w Version-
ZyxelZld Version >= 4.30 <= 5.37
   ZyxelVpn100 Version-
   ZyxelVpn1000 Version-
   ZyxelVpn300 Version-
   ZyxelVpn50 Version-
ZyxelNwa110ax Firmware Version < 6.70\(abtg.0\)
   ZyxelNwa110ax Version-
ZyxelNwa1123acv3 Firmware Version < 6.70\(abvt.0\)
   ZyxelNwa1123acv3 Version-
ZyxelNwa210ax Firmware Version < 6.70\(abtd.0\)
   ZyxelNwa210ax Version-
ZyxelNwa220ax-6e Firmware Version < 6.70\(acco.0\)
   ZyxelNwa220ax-6e Version-
ZyxelNwa50ax Firmware Version < 6.80\(abyw.0\)
   ZyxelNwa50ax Version-
ZyxelNwa50ax-pro Firmware Version < 6.80\(acge.0\)
   ZyxelNwa50ax-pro Version-
ZyxelNwa55axe Firmware Version < 6.80\(abzl.0\)
   ZyxelNwa55axe Version-
ZyxelNwa90ax Firmware Version < 6.80\(accv.0\)
   ZyxelNwa90ax Version-
ZyxelNwa90ax-pro Firmware Version < 6.80\(acgf.0\)
   ZyxelNwa90ax-pro Version-
ZyxelWac500 Firmware Version < 6.70\(abvs.0\)
   ZyxelWac500 Version-
ZyxelWac500h Firmware Version < 6.70\(abwa.0\)
   ZyxelWac500h Version-
ZyxelWax510d Firmware Version < 6.70\(abtf.0\)
   ZyxelWax510d Version-
ZyxelWax610d Firmware Version < 6.70\(abte.0\)
   ZyxelWax610d Version-
ZyxelWax620d-6e Firmware Version < 6.70\(accn.0\)
   ZyxelWax620d-6e Version-
ZyxelWax630s Firmware Version < 6.70\(abzd.0\)
   ZyxelWax630s Version-
ZyxelWax640s-6e Firmware Version < 6.70\(accm.0\)
   ZyxelWax640s-6e Version-
ZyxelWax650s Firmware Version < 6.70\(abrm.0\)
   ZyxelWax650s Version-
ZyxelWax655e Firmware Version < 6.70\(acdo.0\)
   ZyxelWax655e Version-
ZyxelWbe660s Firmware Version < 6.70\(acgg.0\)
   ZyxelWbe660s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.16
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
security@zyxel.com.tw 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.