CVE Feed

    Dashboard / CVE / CVE-2019-12583

    CVE-2019-12583

    Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.

    Published:Jun 27, 2019
    Last Modified:Nov 21, 2024
    EPS:Jun 27, 2019
    EPSS Score:0.59063
    CVSS Score:9.1

    Affected Products

    Vendor
    Zyxel
    Product
    Uag2100
    Vendor
    Zyxel
    Product
    Uag2100 Firmware
    Vendor
    Zyxel
    Product
    Uag4100
    Vendor
    Zyxel
    Product
    Uag4100 Firmware
    Vendor
    Zyxel
    Product
    Uag5100
    Vendor
    Zyxel
    Product
    Uag5100 Firmware
    Vendor
    Zyxel
    Product
    Usg110
    Vendor
    Zyxel
    Product
    Usg1100
    Vendor
    Zyxel
    Product
    Usg1100 Firmware
    Vendor
    Zyxel
    Product
    Usg110 Firmware
    Vendor
    Zyxel
    Product
    Usg1900
    Vendor
    Zyxel
    Product
    Usg1900 Firmware
    Vendor
    Zyxel
    Product
    Usg210
    Vendor
    Zyxel
    Product
    Usg210 Firmware
    Vendor
    Zyxel
    Product
    Usg2200-vpn
    Vendor
    Zyxel
    Product
    Usg2200-vpn Firmware
    Vendor
    Zyxel
    Product
    Usg310
    Vendor
    Zyxel
    Product
    Usg310 Firmware
    Vendor
    Zyxel
    Product
    Zywall 110
    Vendor
    Zyxel
    Product
    Zywall 1100
    Vendor
    Zyxel
    Product
    Zywall 1100 Firmware
    Vendor
    Zyxel
    Product
    Zywall 110 Firmware
    Vendor
    Zyxel
    Product
    Zywall 310
    Vendor
    Zyxel
    Product
    Zywall 310 Firmware
    Vendor
    Zyxel
    Product
    Zywall Vpn100
    Vendor
    Zyxel
    Product
    Zywall Vpn100 Firmware
    Vendor
    Zyxel
    Product
    Zywall Vpn300
    Vendor
    Zyxel
    Product
    Zywall Vpn300 Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High