Description
A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN series firmware versions 4.32 through 5.21, that could allow an authenticated attacker to bypass the second authentication phase to connect the IPsec VPN server even though the two-factor authentication (2FA) was enabled.
Published: 2022-05-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-15940 A downgrade from two-factor authentication to one-factor authentication vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.32 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, and VPN series firmware versions 4.32 through 5.21, that could allow an authenticated attacker to bypass the second authentication phase to connect the IPsec VPN server even though the two-factor authentication (2FA) was enabled.
History

No history.

Subscriptions

Zyxel Atp100 Atp100 Firmware Atp100w Atp100w Firmware Atp200 Atp200 Firmware Atp500 Atp500 Firmware Atp700 Atp700 Firmware Atp800 Atp800 Firmware Usg20 Usg200 Usg200 Firmware Usg20 Firmware Usg210 Usg210 Firmware Usg2200 Usg2200 Firmware Usg300 Usg300 Firmware Usg310 Usg310 Firmware Usg 110 Usg 1100 Usg 1100 Firmware Usg 110 Firmware Usg 1900 Usg 1900 Firmware Usg 20w Usg 20w-vpn Usg 20w-vpn Firmware Usg 20w Firmware Usg 2200-vpn Usg 2200-vpn Firmware Usg 310 Usg 310 Firmware Usg 40 Usg 40 Firmware Usg 40w Usg 40w Firmware Usg 60 Usg 60 Firmware Usg 60w Usg 60w Firmware Usg Flex 100 Usg Flex 100 Firmware Usg Flex 100w Usg Flex 100w Firmware Usg Flex 200 Usg Flex 200 Firmware Usg Flex 500 Usg Flex 500 Firmware Usg Flex 700 Usg Flex 700 Firmware Vpn100 Vpn1000 Vpn1000 Firmware Vpn100 Firmware Vpn300 Vpn300 Firmware Vpn50 Vpn50 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2024-08-02T23:47:42.905Z

Reserved: 2022-03-10T00:00:00.000Z

Link: CVE-2022-0910

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-24T03:15:09.150

Modified: 2024-11-21T06:39:39.087

Link: CVE-2022-0910

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses