First published: Thu Jun 27 2019(Updated: )
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel Uag2100 Firmware | <=4.18\(aaiz.1\)c0 | |
Zyxel Uag2100 | ||
Zyxel Uag4100 Firmware | <=4.18\(aatd.1\)c0 | |
Zyxel Uag4100 | ||
Zyxel Uag5100 Firmware | <=4.18\(aapn.1\)c0 | |
Zyxel Uag5100 | ||
Zyxel Usg110 Firmware | <=4.33\(aaph.0\)c0 | |
Zyxel Usg110 | ||
Zyxel Usg210 Firmware | <=4.33\(aapi.0\)c0 | |
Zyxel Usg210 | ||
Zyxel Usg310 Firmware | <=4.33\(aapj.0\)c0 | |
Zyxel Usg310 | ||
Zyxel Usg1100 Firmware | <=4.33\(aapk.0\)c0 | |
Zyxel Usg1100 | ||
Zyxel Usg1900 Firmware | <=4.33\(aapl.0\)c0 | |
Zyxel Usg1900 | ||
Zyxel Usg2200-vpn Firmware | <=4.33\(abae.0\)c0 | |
Zyxel Usg2200-vpn | ||
Zyxel Zywall Vpn100 Firmware | <=10.02\(abfv.0\)c0 | |
Zyxel Zywall Vpn100 | ||
Zyxel Zywall Vpn300 Firmware | <=10.02\(abfc.0\)c0 | |
Zyxel Zywall Vpn300 | ||
Zyxel Zywall 110 Firmware | <=4.33\(aaaa.0\)c0 | |
Zyxel Zywall 110 | ||
Zyxel Zywall 310 Firmware | <=4.33\(aaab.0\)c0 | |
Zyxel Zywall 310 | ||
Zyxel Zywall 1100 Firmware | <=4.33\(aaac.0\)c0 | |
Zyxel Zywall 1100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-12583.
The severity of CVE-2019-12583 is critical with a CVSS score of 9.1.
Several Zyxel UAG, USG, and ZyWall devices are affected by CVE-2019-12583. Specifically, Zyxel UAG2100 Firmware up to version 4.18(aaiz.1)c0, Zyxel UAG4100 Firmware up to version 4.18(aatd.1)c0, Zyxel UAG5100 Firmware up to version 4.18(aapn.1)c0, Zyxel USG110 Firmware up to version 4.33(aaph.0)c0, Zyxel USG210 Firmware up to version 4.33(aapi.0)c0, Zyxel USG310 Firmware up to version 4.33(aapj.0)c0, Zyxel USG1100 Firmware up to version 4.33(aapk.0)c0, Zyxel USG1900 Firmware up to version 4.33(aapl.0)c0, Zyxel USG2200-vpn Firmware up to version 4.33(abae.0)c0, Zyxel Zywall Vpn100 Firmware up to version 10.02(abfv.0)c0, Zyxel Zywall Vpn300 Firmware up to version 10.02(abfc.0)c0, Zyxel Zywall 110 Firmware up to version 4.33(aaaa.0)c0, Zyxel Zywall 310 Firmware up to version 4.33(aaab.0)c0, and Zyxel Zywall 1100 Firmware up to version 4.33(aaac.0)c0.
The impact of CVE-2019-12583 is that a remote attacker can generate guest accounts by directly accessing the account generator, leading to unauthorized network access or denial of service.
To fix CVE-2019-12583, it is recommended to update the firmware of the affected Zyxel UAG, USG, and ZyWall devices to a version that includes a fix for this vulnerability. Contact Zyxel for further assistance.