CVE Feed

    Dashboard / CVE / CVE-2020-29299

    CVE-2020-29299

    Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38, and NSG before 1.33 patch 4.

    Published:Dec 27, 2020
    Last Modified:Nov 21, 2024
    EPS:Dec 27, 2020
    EPSS Score:0.0361
    CVSS Score:7.2

    Affected Products

    Vendor
    Zyxel
    Product
    Atp
    Vendor
    Zyxel
    Product
    Nsg
    Vendor
    Zyxel
    Product
    Nsg Firmware
    Vendor
    Zyxel
    Product
    Usg Flex
    Vendor
    Zyxel
    Product
    Usg Flex Firmware
    Vendor
    Zyxel
    Product
    Vpn Orchestrator
    Vendor
    Zyxel
    Product
    Zld

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High