Improper Privilege Management in ZyXEL Communications Corp. products - CVE-2023-5650

 

Improper Privilege Management in ZyXEL Communications Corp. products - CVE-2023-5650

Published: November 28, 2023


Vulnerability identifier: #VU83522
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5650
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper privilege management in the ZySH. A local user can modify the URL of the registration page in the web GUI of the target device.


Affected software

ATP series
USG FLEX series
VPN series
USG FLEX 50W
USG20W-VPN

How to mitigate CVE-2023-5650

Install updates from vendor's website.

ATP series - update to 5.37 Patch 1
USG FLEX series - update to 5.37 Patch 1
USG FLEX 50W - update to 5.37 Patch 1
USG20W-VPN - update to 5.37 Patch 1
VPN series - update to 5.37 Patch 1

External References

Related Security Bulletins