CVE-2019-12583
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.
Published:Jun 27, 2019
Last Modified:Nov 21, 2024
EPS:Jun 27, 2019
EPSS Score:0.59063
CVSS Score:9.1
Affected Products
Vendor
Product
Action
Vendor
Zyxel
Product
Uag2100
Zyxel
Uag2100
Vendor
Zyxel
Product
Uag2100 Firmware
Zyxel
Uag2100 Firmware
Vendor
Zyxel
Product
Uag4100
Zyxel
Uag4100
Vendor
Zyxel
Product
Uag4100 Firmware
Zyxel
Uag4100 Firmware
Vendor
Zyxel
Product
Uag5100
Zyxel
Uag5100
Vendor
Zyxel
Product
Uag5100 Firmware
Zyxel
Uag5100 Firmware
Vendor
Zyxel
Product
Usg110
Zyxel
Usg110
Vendor
Zyxel
Product
Usg1100
Zyxel
Usg1100
Vendor
Zyxel
Product
Usg1100 Firmware
Zyxel
Usg1100 Firmware
Vendor
Zyxel
Product
Usg110 Firmware
Zyxel
Usg110 Firmware
Vendor
Zyxel
Product
Usg1900
Zyxel
Usg1900
Vendor
Zyxel
Product
Usg1900 Firmware
Zyxel
Usg1900 Firmware
Vendor
Zyxel
Product
Usg210
Zyxel
Usg210
Vendor
Zyxel
Product
Usg210 Firmware
Zyxel
Usg210 Firmware
Vendor
Zyxel
Product
Usg2200-vpn
Zyxel
Usg2200-vpn
Vendor
Zyxel
Product
Usg2200-vpn Firmware
Zyxel
Usg2200-vpn Firmware
Vendor
Zyxel
Product
Usg310
Zyxel
Usg310
Vendor
Zyxel
Product
Usg310 Firmware
Zyxel
Usg310 Firmware
Vendor
Zyxel
Product
Zywall 110
Zyxel
Zywall 110
Vendor
Zyxel
Product
Zywall 1100
Zyxel
Zywall 1100
Vendor
Zyxel
Product
Zywall 1100 Firmware
Zyxel
Zywall 1100 Firmware
Vendor
Zyxel
Product
Zywall 110 Firmware
Zyxel
Zywall 110 Firmware
Vendor
Zyxel
Product
Zywall 310
Zyxel
Zywall 310
Vendor
Zyxel
Product
Zywall 310 Firmware
Zyxel
Zywall 310 Firmware
Vendor
Zyxel
Product
Zywall Vpn100
Zyxel
Zywall Vpn100
Vendor
Zyxel
Product
Zywall Vpn100 Firmware
Zyxel
Zywall Vpn100 Firmware
Vendor
Zyxel
Product
Zywall Vpn300
Zyxel
Zywall Vpn300
Vendor
Zyxel
Product
Zywall Vpn300 Firmware
Zyxel
Zywall Vpn300 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
