Improper Privilege Management in ZyXEL Communications Corp. products - CVE-2023-5650
Published: November 28, 2023
Vulnerability identifier: #VU83522
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5650
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper privilege management in the ZySH. A local user can modify the URL of the registration page in the web GUI of the target device.
Affected software
ATP series
USG FLEX series
VPN series
USG FLEX 50W
USG20W-VPN
USG FLEX series
VPN series
USG FLEX 50W
USG20W-VPN
How to mitigate CVE-2023-5650
Install updates from vendor's website.
ATP series - update to 5.37 Patch 1
USG FLEX series - update to 5.37 Patch 1
USG FLEX 50W - update to 5.37 Patch 1
USG20W-VPN - update to 5.37 Patch 1
VPN series - update to 5.37 Patch 1
USG FLEX series - update to 5.37 Patch 1
USG FLEX 50W - update to 5.37 Patch 1
USG20W-VPN - update to 5.37 Patch 1
VPN series - update to 5.37 Patch 1