Improper Authentication in ZyXEL Communications Corp. products - CVE-2022-0342

 

Improper Authentication in ZyXEL Communications Corp. products - CVE-2022-0342

Published: March 30, 2022


Vulnerability identifier: #VU61723
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0342
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to missing authentication checks in the web interface. A remote attacker can bypass authentication process and obtain administrative access to the device.


Affected software

NSG series
ATP series
USG series
VPN series
USG FLEX series
ZyWALL

How to mitigate CVE-2022-0342

Install updates from vendor's website.

NSG series - update to 1.33p4_WK11
USG series - update to 4.71
ZyWALL - update to 4.71
VPN series - update to 5.21
USG FLEX series - update to 5.21 Patch 1
ATP series - update to 5.21 Patch 1

External References

Related Security Bulletins