ZeroHour

CVE-2023-5960

CVSS 3.1
5.5 medium
EPSS
<1%p12
Published
()
Modified
Description

An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series firmware versions 4.30 through 5.37 could allow an authenticated local attacker to access the system files on an affected device.

Vendors
zyxel
Products
zld
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news