Improper Privilege Management in Zyxel ATP, USG FLEX, and NWA Series Firmware
CVE-2023-5797
5.5MEDIUM
Key Information:
- Vendor
Zyxel
- Status
- Vendor
- CVE Published:
- 28 November 2023
What is CVE-2023-5797?
An improper privilege management vulnerability exists in the debug CLI command of various Zyxel firmware products, allowing an authenticated local attacker to exploit this weakness. By leveraging this vulnerability, the attacker could potentially access sensitive administrator logs, thereby compromising the confidentiality and integrity of device management logs across several series, including ATP, USG FLEX, and various Access Points. It's crucial for users to apply the necessary patches and updates to secure their devices against possible exploitation.
Affected Version(s)
ATP series firmware versions 4.32 through 5.37
NWA50AX firmware 6.29(ABYW.2)
USG FLEX 50(W) series firmware versions 4.16 through 5.37