SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-46387

ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS).

MEDIUM 6.1EPSS 21.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 21.0%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads to bypass security restriction to achieve Cross Site Scripting, which allows an attacker able to execute arbitrary JavaScript codes to perform multiple attacks such as clipboard hijacking and session hijacking.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
20.95% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
zyxel/zywall 2 plus internet security appliance firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.