Lucene search

K
cve[email protected]CVE-2022-45440
HistoryJan 17, 2023 - 2:15 a.m.

CVE-2022-45440

2023-01-1702:15:09
CWE-59
CWE-552
web.nvd.nist.gov
19
cve-2022-45440
zyxel
ax7501-b0
ftp server
vulnerability
firmware
symbolic links
external storage media
usb flash drive
nvd

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

4.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

A vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0, which processes symbolic links on external storage media. A local authenticated attacker with administrator privileges could abuse this vulnerability to access the root file system by creating a symbolic link on external storage media, such as a USB flash drive, and then logging into the FTP server on a vulnerable device.

Affected configurations

NVD
Node
zyxelax7501-b0_firmwareRange<5.17\(abpc.3\)c0
AND
zyxelax7501-b0Match-

CNA Affected

[
  {
    "vendor": "Zyxel",
    "product": "AX7501-B0 firmware",
    "versions": [
      {
        "version": "< V5.17(ABPC.3)C0",
        "status": "affected"
      }
    ]
  }
]

4.4 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

4.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2022-45440