First published: Tue Nov 07 2023(Updated: )
The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel Gs1900-48hpv2 Firmware | <=2.70\(abtq.5\) | |
Zyxel Gs1900-48hpv2 | ||
Zyxel Gs1900-48 Firmware | <=2.70\(aahn.5\) | |
Zyxel GS1900-48 | ||
Zyxel Gs1900-24hpv2 Firmware | <=2.70\(abtp.5\) | |
Zyxel Gs1900-24hpv2 | ||
Zyxel Gs1900-24ep Firmware | <=2.70\(abto.5\) | |
Zyxel GS1900-24EP | ||
Zyxel Gs1900-24e Firmware | <=2.70\(aahk.5\) | |
Zyxel GS1900-24E | ||
Zyxel Gs1900-24 Firmware | <=2.70\(aahl.5\) | |
Zyxel GS1900-24 | ||
Zyxel Gs1900-16 Firmware | <=2.70\(aahj.5\) | |
Zyxel Gs1900-16 | ||
Zyxel GS1900-10HP firmware | <=2.70\(aazi.5\) | |
Zyxel GS1900-10HP | ||
Zyxel Gs1900-8hp Firmware | <=2.70\(aahi.5\) | |
Zyxel Gs1900-8hp | ||
Zyxel GS1900-8 firmware | <=2.70\(aahh.5\) | |
Zyxel GS1900-8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-35140.
The severity of CVE-2023-35140 is medium with a CVSS score of 5.5.
The vulnerability allows an authenticated local user with read-only access to modify system settings on a vulnerable device.
The Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) is affected by CVE-2023-35140.
To fix the vulnerability, update the Zyxel GS1900-24EP switch firmware to a version that is not vulnerable.