Improper Privilege Management in Zyxel ATP, USG FLEX, and NWA Series Firmware
CVE-2023-5797

5.5MEDIUM

Key Information:

Summary

An improper privilege management vulnerability exists in the debug CLI command of various Zyxel firmware products, allowing an authenticated local attacker to exploit this weakness. By leveraging this vulnerability, the attacker could potentially access sensitive administrator logs, thereby compromising the confidentiality and integrity of device management logs across several series, including ATP, USG FLEX, and various Access Points. It's crucial for users to apply the necessary patches and updates to secure their devices against possible exploitation.

Affected Version(s)

ATP series firmware versions 4.32 through 5.37

NWA50AX firmware 6.29(ABYW.2)

USG FLEX 50(W) series firmware versions 4.16 through 5.37

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.