CVE-2019-12583
PoC —CVSS 3.0
9.1 critical
EPSS
44%p99
Published
()
Modified
Description
Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.
- Vendors
- zyxel
- Products
- uag2100 firmware, uag4100 firmware, uag5100 firmware, usg110 firmware, usg210 firmware, usg310 firmware, usg1100 firmware, usg1900 firmware, usg2200-vpn firmware, zywall vpn100 firmware, zywall vpn300 firmware, zywall 110 firmware
- Weakness
- CWE-425
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.