Lucene search

K
cve[email protected]CVE-2023-5797
HistoryNov 28, 2023 - 3:15 a.m.

CVE-2023-5797

2023-11-2803:15:07
CWE-269
web.nvd.nist.gov
23
cve-2023-5797
zyxel atp
usg flex
vulnerability
firmware
privilege management
cli
authenticated attacker
nvd

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, NWA50AX firmware version 6.29(ABYW.2), WAC500 firmware version 6.65(ABVS.1), WAX300H firmware version 6.60(ACHF.1), and WBE660S firmware version 6.65(ACGG.1), could allow an authenticated local attacker to access the administrator’s logs on an affected device.

Affected configurations

NVD
Node
zyxelzldRange4.32–5.37
AND
zyxelatp100Match-
OR
zyxelatp100wMatch-
OR
zyxelatp200Match-
OR
zyxelatp500Match-
OR
zyxelatp700Match-
OR
zyxelatp800Match-
Node
zyxelzldRange4.50–5.37
AND
zyxelusg_flex_100Match-
OR
zyxelusg_flex_100wMatch-
OR
zyxelusg_flex_200Match-
OR
zyxelusg_flex_50Match-
OR
zyxelusg_flex_500Match-
OR
zyxelusg_flex_50wMatch-
OR
zyxelusg_flex_700Match-
Node
zyxelzldRange4.16–5.37
AND
zyxelusg_20w-vpnMatch-
OR
zyxelvpn50wMatch-
Node
zyxelzldRange4.30–5.37
AND
zyxelvpn100Match-
OR
zyxelvpn1000Match-
OR
zyxelvpn300Match-
OR
zyxelvpn50Match-
Node
zyxelnwa110ax_firmwareRange<6.70\(abtg.0\)
AND
zyxelnwa110axMatch-
Node
zyxelnwa1123acv3_firmwareRange<6.70\(abvt.0\)
AND
zyxelnwa1123acv3Match-
Node
zyxelnwa210ax_firmwareRange<6.70\(abtd.0\)
AND
zyxelnwa210axMatch-
Node
zyxelnwa220ax-6e_firmwareRange<6.70\(acco.0\)
AND
zyxelnwa220ax-6eMatch-
Node
zyxelnwa50ax_firmwareRange<6.80\(abyw.0\)
AND
zyxelnwa50axMatch-
Node
zyxelnwa50ax-pro_firmwareRange<6.80\(acge.0\)
AND
zyxelnwa50ax-proMatch-
Node
zyxelnwa55axe_firmwareRange<6.80\(abzl.0\)
AND
zyxelnwa55axeMatch-
Node
zyxelnwa90ax_firmwareRange<6.80\(accv.0\)
AND
zyxelnwa90axMatch-
Node
zyxelnwa90ax-pro_firmwareRange<6.80\(acgf.0\)
AND
zyxelnwa90ax-proMatch-
Node
zyxelwac500_firmwareRange<6.70\(abvs.0\)
AND
zyxelwac500Match-
Node
zyxelwac500h_firmwareRange<6.70\(abwa.0\)
AND
zyxelwac500hMatch-
Node
zyxelwax510d_firmwareRange<6.70\(abtf.0\)
AND
zyxelwax510dMatch-
Node
zyxelwax610d_firmwareRange<6.70\(abte.0\)
AND
zyxelwax610dMatch-
Node
zyxelwax620d-6e_firmwareRange<6.70\(accn.0\)
AND
zyxelwax620d-6eMatch-
Node
zyxelwax630s_firmwareRange<6.70\(abzd.0\)
AND
zyxelwax630sMatch-
Node
zyxelwax640s-6e_firmwareRange<6.70\(accm.0\)
AND
zyxelwax640s-6eMatch-
Node
zyxelwax650s_firmwareRange<6.70\(abrm.0\)
AND
zyxelwax650sMatch-
Node
zyxelwax655e_firmwareRange<6.70\(acdo.0\)
AND
zyxelwax655eMatch-
Node
zyxelwbe660s_firmwareRange<6.70\(acgg.0\)
AND
zyxelwbe660sMatch-
CPENameOperatorVersion
zyxel:zldzyxel zldle5.37

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "ATP series firmware",
    "vendor": "Zyxel",
    "versions": [
      {
        "status": "affected",
        "version": " versions 4.32 through 5.37"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "USG FLEX series firmware",
    "vendor": "Zyxel",
    "versions": [
      {
        "status": "affected",
        "version": "versions 4.50 through 5.37"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "USG FLEX 50(W) series firmware",
    "vendor": "Zyxel",
    "versions": [
      {
        "status": "affected",
        "version": "versions 4.16 through 5.37"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "USG20(W)-VPN series firmware",
    "vendor": "Zyxel",
    "versions": [
      {
        "status": "affected",
        "version": "versions 4.16 through 5.37"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "VPN series firmware",
    "vendor": "Zyxel",
    "versions": [
      {
        "status": "affected",
        "version": "versions 4.30 through 5.37"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "NWA50AX firmware",
    "vendor": "Zyxel",
    "versions": [
      {
        "status": "affected",
        "version": "6.29(ABYW.2)"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "WAC500 firmware",
    "vendor": "Zyxel",
    "versions": [
      {
        "status": "affected",
        "version": "6.65(ABVS.1)"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "WAX300H firmware",
    "vendor": "Zyxel",
    "versions": [
      {
        "status": "affected",
        "version": "6.60(ACHF.1)"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "WBE660S firmware",
    "vendor": "Zyxel",
    "versions": [
      {
        "status": "affected",
        "version": "6.65(ACGG.1)"
      }
    ]
  }
]

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2023-5797