Lucene search

K
cvelistZyxelCVELIST:CVE-2021-35029
HistoryJul 02, 2021 - 10:29 a.m.

CVE-2021-35029

2021-07-0210:29:07
CWE-287
Zyxel
www.cve.org
6
zyxel
web management
authentication bypass
firmware
remote attacker
arbitrary commands

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.007

Percentile

80.3%

An authentication bypasss vulnerability in the web-based management interface of Zyxel USG/Zywall series firmware versions 4.35 through 4.64 and USG Flex, ATP, and VPN series firmware versions 4.35 through 5.01, which could allow a remote attacker to execute arbitrary commands on an affected device.

CNA Affected

[
  {
    "product": "USG/Zywall series Firmware",
    "vendor": "Zyxel",
    "versions": [
      {
        "status": "affected",
        "version": "4.35 through 4.64"
      }
    ]
  },
  {
    "product": "USG FLEX series Firmware",
    "vendor": "Zyxel",
    "versions": [
      {
        "status": "affected",
        "version": "4.35 through 5.01"
      }
    ]
  },
  {
    "product": "ATP series Firmware",
    "vendor": "Zyxel",
    "versions": [
      {
        "status": "affected",
        "version": "4.35 through 5.01"
      }
    ]
  },
  {
    "product": "VPN series Firmware",
    "vendor": "Zyxel",
    "versions": [
      {
        "status": "affected",
        "version": "4.35 through 5.01"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.007

Percentile

80.3%

Related for CVELIST:CVE-2021-35029