Metrics
No CVSS v4.0
Attack Vector Local
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Confidentiality Impact High
Integrity Impact None
Availability Impact None
User Interaction None
No CVSS v3.0
No CVSS v2
This CVE is not in the KEV list.
The EPSS score is 0.00072.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Zyxel
Subscribe
|
Atp100
Subscribe
Atp100w
Subscribe
Atp200
Subscribe
Atp500
Subscribe
Atp700
Subscribe
Atp800
Subscribe
Nwa110ax
Subscribe
Nwa110ax Firmware
Subscribe
Nwa1123acv3
Subscribe
Nwa1123acv3 Firmware
Subscribe
Nwa210ax
Subscribe
Nwa210ax Firmware
Subscribe
Nwa220ax-6e
Subscribe
Nwa220ax-6e Firmware
Subscribe
Nwa50ax
Subscribe
Nwa50ax-pro
Subscribe
Nwa50ax-pro Firmware
Subscribe
Nwa50ax Firmware
Subscribe
Nwa55axe
Subscribe
Nwa55axe Firmware
Subscribe
Nwa90ax
Subscribe
Nwa90ax-pro
Subscribe
Nwa90ax-pro Firmware
Subscribe
Nwa90ax Firmware
Subscribe
Usg 20w-vpn
Subscribe
Usg Flex 100
Subscribe
Usg Flex 100w
Subscribe
Usg Flex 200
Subscribe
Usg Flex 50
Subscribe
Usg Flex 500
Subscribe
Usg Flex 50w
Subscribe
Usg Flex 700
Subscribe
Vpn100
Subscribe
Vpn1000
Subscribe
Vpn300
Subscribe
Vpn50
Subscribe
Vpn50w
Subscribe
Wac500
Subscribe
Wac500 Firmware
Subscribe
Wac500h
Subscribe
Wac500h Firmware
Subscribe
Wax510d
Subscribe
Wax510d Firmware
Subscribe
Wax610d
Subscribe
Wax610d Firmware
Subscribe
Wax620d-6e
Subscribe
Wax620d-6e Firmware
Subscribe
Wax630s
Subscribe
Wax630s Firmware
Subscribe
Wax640s-6e
Subscribe
Wax640s-6e Firmware
Subscribe
Wax650s
Subscribe
Wax650s Firmware
Subscribe
Wax655e
Subscribe
Wax655e Firmware
Subscribe
Wbe660s
Subscribe
Wbe660s Firmware
Subscribe
Zld
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
Configuration 22 [-]
| AND |
|
Configuration 23 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41778 | An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, NWA50AX firmware version 6.29(ABYW.2), WAC500 firmware version 6.65(ABVS.1), WAX300H firmware version 6.60(ACHF.1), and WBE660S firmware version 6.65(ACGG.1), could allow an authenticated local attacker to access system files on an affected device. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zyxel
Published:
Updated: 2024-08-02T17:23:27.715Z
Reserved: 2023-07-11T01:52:33.655Z
Link: CVE-2023-37925
No data.
Status : Modified
Published: 2023-11-28T02:15:42.547
Modified: 2024-11-21T08:12:29.060
Link: CVE-2023-37925
No data.
OpenCVE Enrichment
No data.
EUVD