HIGH🇵🇱 Wersja polska

CVE-2019-15799

CVSS 8.8v3.1pub. 2019-11-14upd. 2024-11-21

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, when given non-admin level privileges, have the same level of privileged access as administrators when connecting to the device via SSH (while their permissions via the web interface are in fact restricted). This allows normal users to obtain the administrative password by running the tech-support command via the CLI: this contains the encrypted passwords for all users on the device. As these passwords are encrypted using well-known and static parameters, they can be decrypted and the original passwords (including the administrator password) can be obtained.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Zyxel Gs1900 10hp

    HW
    Zyxel
    all versions
  • Zyxel Gs1900 10hp Firmware

    OS
    Zyxel
    < 2.50\(aazi.0\)c0
  • Zyxel Gs1900 16

    HW
    Zyxel
    all versions
  • Zyxel Gs1900 16 Firmware

    OS
    Zyxel
    < 2.50\(aahj.0\)c0
  • Zyxel Gs1900 24

    HW
    Zyxel
    all versions
  • Zyxel Gs1900 24e

    HW
    Zyxel
    all versions
  • Zyxel Gs1900 24e Firmware

    OS
    Zyxel
    < 2.50\(aahk.0\)c0
  • Zyxel Gs1900 24 Firmware

    OS
    Zyxel
    < 2.50\(aahl.0\)c0
  • Zyxel Gs1900 24hp

    HW
    Zyxel
    all versions
  • Zyxel Gs1900 24hp Firmware

    OS
    Zyxel
    < 2.50\(aahm.0\)c0
  • Zyxel Gs1900 48

    HW
    Zyxel
    all versions
  • Zyxel Gs1900 48 Firmware

    OS
    Zyxel
    < 2.50\(aahn.0\)c0
  • Zyxel Gs1900 48hp

    HW
    Zyxel
    all versions
  • Zyxel Gs1900 48hp Firmware

    OS
    Zyxel
    < 2.50\(aaho.0\)c0
  • Zyxel Gs1900 8

    HW
    Zyxel
    all versions
  • Zyxel Gs1900 8 Firmware

    OS
    Zyxel
    < 2.50\(aahh.0\)c0
  • Zyxel Gs1900 8hp

    HW
    Zyxel
    all versions
  • Zyxel Gs1900 8hp Firmware

    OS
    Zyxel
    < 2.50\(aahi.0\)c0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-15800CRITICAL9.8PL ✓same product

Zyxel GS1900 — command injection w bibliotece libclicmd.so (RCE)

CVE-2019-15803CRITICAL9.1PL ✓same product

Zyxel GS1900: Auth Bypass w ukrytej powłoce diagnostycznej

CVE-2016-1329CRITICAL9.8PL ✓same product

Cisco NX-OS: Hardcoded credentials umożliwiające zdalny dostęp root

CVE-2015-5988CRITICAL9.8PL ✓same product

Puste hasło w interfejsie webowym Belkin F9K1102 — pełny dostęp administracyjny

CVE-2015-5989CRITICAL9.8PL ✓same product

Obejście autoryzacji po stronie klienta w Belkin F9K1102 2