CVE-2019-12583: Critical severity zyxel uag2100 vulnerability
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-12583.
What is the severity of CVE-2019-12583?
The severity of CVE-2019-12583 is critical with a CVSS score of 9.1.
Which devices are affected by CVE-2019-12583?
Several Zyxel UAG, USG, and ZyWall devices are affected by CVE-2019-12583. Specifically, Zyxel UAG2100 Firmware up to version 4.18(aaiz.1)c0, Zyxel UAG4100 Firmware up to version 4.18(aatd.1)c0, Zyxel UAG5100 Firmware up to version 4.18(aapn.1)c0, Zyxel USG110 Firmware up to version 4.33(aaph.0)c0, Zyxel USG210 Firmware up to version 4.33(aapi.0)c0, Zyxel USG310 Firmware up to version 4.33(aapj.0)c0, Zyxel USG1100 Firmware up to version 4.33(aapk.0)c0, Zyxel USG1900 Firmware up to version 4.33(aapl.0)c0, Zyxel USG2200-vpn Firmware up to version 4.33(abae.0)c0, Zyxel Zywall Vpn100 Firmware up to version 10.02(abfv.0)c0, Zyxel Zywall Vpn300 Firmware up to version 10.02(abfc.0)c0, Zyxel Zywall 110 Firmware up to version 4.33(aaaa.0)c0, Zyxel Zywall 310 Firmware up to version 4.33(aaab.0)c0, and Zyxel Zywall 1100 Firmware up to version 4.33(aaac.0)c0.
What is the impact of CVE-2019-12583?
The impact of CVE-2019-12583 is that a remote attacker can generate guest accounts by directly accessing the account generator, leading to unauthorized network access or denial of service.
How can I fix CVE-2019-12583?
To fix CVE-2019-12583, it is recommended to update the firmware of the affected Zyxel UAG, USG, and ZyWall devices to a version that includes a fix for this vulnerability. Contact Zyxel for further assistance.