VulnerabilityModified
CVE-2019-12583
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator.
CRITICAL 9.1EPSS 43.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 43.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 43.93% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-425
- Affected
- zyxel/uag2100 firmware · zyxel/uag4100 firmware · zyxel/uag5100 firmware · zyxel/usg110 firmware · zyxel/usg210 firmware · zyxel/usg310 firmware · zyxel/usg1100 firmware · zyxel/usg1900 firmware · zyxel/usg2200-vpn firmware · zyxel/zywall vpn100 firmware · zyxel/zywall vpn300 firmware · zyxel/zywall 110 firmware · zyxel/zywall 310 firmware · zyxel/zywall 1100 firmware
- Source
- cve@mitre.org
References
- https://n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generator-xss/Exploit, Third Party Advisory
- https://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtmlPatch, Vendor Advisory
- https://n-thumann.de/blog/zyxel-gateways-missing-access-control-in-account-generator-xss/Exploit, Third Party Advisory
- https://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.