An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, NWA50AX firmware version 6.29(ABYW.2), WAC500 firmware version 6.65(ABVS.1), WAX300H firmware version 6.60(ACHF.1), and WBE660S firmware version 6.65(ACGG.1), could allow an authenticated local attacker to access system files on an affected device.

Project Subscriptions

Vendors Products
Atp100w Subscribe
Nwa110ax Subscribe
Nwa110ax Firmware Subscribe
Nwa1123acv3 Subscribe
Nwa1123acv3 Firmware Subscribe
Nwa210ax Subscribe
Nwa210ax Firmware Subscribe
Nwa220ax-6e Subscribe
Nwa220ax-6e Firmware Subscribe
Nwa50ax Subscribe
Nwa50ax-pro Subscribe
Nwa50ax-pro Firmware Subscribe
Nwa50ax Firmware Subscribe
Nwa55axe Subscribe
Nwa55axe Firmware Subscribe
Nwa90ax Subscribe
Nwa90ax-pro Subscribe
Nwa90ax-pro Firmware Subscribe
Nwa90ax Firmware Subscribe
Usg 20w-vpn Subscribe
Usg Flex 100 Subscribe
Usg Flex 100w Subscribe
Usg Flex 200 Subscribe
Usg Flex 50 Subscribe
Usg Flex 500 Subscribe
Usg Flex 50w Subscribe
Usg Flex 700 Subscribe
Vpn1000 Subscribe
Wac500 Firmware Subscribe
Wac500h Subscribe
Wac500h Firmware Subscribe
Wax510d Subscribe
Wax510d Firmware Subscribe
Wax610d Subscribe
Wax610d Firmware Subscribe
Wax620d-6e Subscribe
Wax620d-6e Firmware Subscribe
Wax630s Subscribe
Wax630s Firmware Subscribe
Wax640s-6e Subscribe
Wax640s-6e Firmware Subscribe
Wax650s Subscribe
Wax650s Firmware Subscribe
Wax655e Subscribe
Wax655e Firmware Subscribe
Wbe660s Subscribe
Wbe660s Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-41778 An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, NWA50AX firmware version 6.29(ABYW.2), WAC500 firmware version 6.65(ABVS.1), WAX300H firmware version 6.60(ACHF.1), and WBE660S firmware version 6.65(ACGG.1), could allow an authenticated local attacker to access system files on an affected device.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2024-08-02T17:23:27.715Z

Reserved: 2023-07-11T01:52:33.655Z

Link: CVE-2023-37925

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-28T02:15:42.547

Modified: 2024-11-21T08:12:29.060

Link: CVE-2023-37925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses