CVE-2023-35140: Medium severity zyxel gs1900-48hpv2 vulnerability
Published Nov 7, 2023
·Updated
The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.
Affected Software
20 affected components
Zyxel Gs1900-48hpv2 Firmware<=2.70\(abtq.5\)
Zyxel Gs1900-48hpv2
Zyxel Gs1900-48 Firmware<=2.70\(aahn.5\)
Zyxel GS1900-48
Zyxel Gs1900-24hpv2 Firmware<=2.70\(abtp.5\)
Zyxel Gs1900-24hpv2
Zyxel Gs1900-24ep Firmware<=2.70\(abto.5\)
Zyxel GS1900-24EP
Zyxel Gs1900-24e Firmware<=2.70\(aahk.5\)
Zyxel GS1900-24E
Zyxel Gs1900-24 Firmware<=2.70\(aahl.5\)
Zyxel GS1900-24
Zyxel Gs1900-16 Firmware<=2.70\(aahj.5\)
Zyxel Gs1900-16
Zyxel GS1900-10HP firmware<=2.70\(aazi.5\)
Zyxel GS1900-10HP
Zyxel GS1900-8HP firmware<=2.70\(aahi.5\)
Zyxel GS1900-8HP
Zyxel GS1900-8 firmware<=2.70\(aahh.5\)
Zyxel GS1900-8
Event History
Nov 7, 2023
CVE Published
01:44 AM
Data Sourced
01:44 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the improper privilege management vulnerability in Zyxel GS1900-24EP switch firmware?
The vulnerability ID is CVE-2023-35140.
2
What is the severity of CVE-2023-35140?
The severity of CVE-2023-35140 is medium with a CVSS score of 5.5.
3
How does the improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) impact the system?
The vulnerability allows an authenticated local user with read-only access to modify system settings on a vulnerable device.
4
Which versions of the Zyxel GS1900-24EP switch firmware are affected by CVE-2023-35140?
The Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) is affected by CVE-2023-35140.
5
How can I fix the improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware?
To fix the vulnerability, update the Zyxel GS1900-24EP switch firmware to a version that is not vulnerable.