CVE Feed

    Dashboard / CVE / CVE-2019-15802

    CVE-2019-15802

    An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts passwords using a hardcoded cryptographic key in sal_util_str_encrypt() in libsal.so.0.0. The parameters (salt, IV, and key data) are used to encrypt and decrypt all passwords using AES256 in CBC mode. With the parameters known, all previously encrypted passwords can be decrypted. This includes the passwords that are part of configuration backups or otherwise embedded as part of the firmware.

    Published:Nov 14, 2019
    Last Modified:Nov 21, 2024
    EPS:Nov 14, 2019
    EPSS Score:0.00286
    CVSS Score:5.9

    Affected Products

    Vendor
    Zyxel
    Product
    Gs1900-10hp
    Vendor
    Zyxel
    Product
    Gs1900-10hp Firmware
    Vendor
    Zyxel
    Product
    Gs1900-16
    Vendor
    Zyxel
    Product
    Gs1900-16 Firmware
    Vendor
    Zyxel
    Product
    Gs1900-24
    Vendor
    Zyxel
    Product
    Gs1900-24 Firmware
    Vendor
    Zyxel
    Product
    Gs1900-24e
    Vendor
    Zyxel
    Product
    Gs1900-24e Firmware
    Vendor
    Zyxel
    Product
    Gs1900-24hp
    Vendor
    Zyxel
    Product
    Gs1900-24hp Firmware
    Vendor
    Zyxel
    Product
    Gs1900-48
    Vendor
    Zyxel
    Product
    Gs1900-48 Firmware
    Vendor
    Zyxel
    Product
    Gs1900-48hp
    Vendor
    Zyxel
    Product
    Gs1900-48hp Firmware
    Vendor
    Zyxel
    Product
    Gs1900-8
    Vendor
    Zyxel
    Product
    Gs1900-8 Firmware
    Vendor
    Zyxel
    Product
    Gs1900-8hp
    Vendor
    Zyxel
    Product
    Gs1900-8hp Firmware

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High