Plaintext Password Security Flaw in Zyxel NAS 326 Device
CVE-2019-10630
8.8HIGH
Summary
A security flaw in Zyxel NAS 326 allows an elevated privileged user to retrieve the admin password in plaintext. This vulnerability arises specifically in version 5.21 of the device, potentially permitting unauthorized access to critical administrative functions. Users of Zyxel NAS 326 should be vigilant and implement security measures to safeguard against unauthorized password retrieval, particularly in environments where sensitive data is stored.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved