Improper Input Validation in Zyxel ATP and USG FLEX Series Firmware
CVE-2023-35136
5.5MEDIUM
Key Information:
- Vendor
- Zyxel
- Status
- Vendor
- CVE Published:
- 28 November 2023
Summary
The Zyxel ATP and USG FLEX series firmware contain an improper input validation vulnerability within the Quagga package. This flaw permits an authenticated local attacker to potentially access sensitive configuration files on the device, which could lead to further unauthorized actions and compromise the device's integrity.
Affected Version(s)
ATP series firmware versions 4.32 through 5.37
USG FLEX 50(W) series firmware versions 4.16 through 5.37
USG FLEX series firmware versions 4.50 through 5.37
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved