9
CVSSv2

CVE-2020-29299

Published: 27/12/2020 Updated: 05/01/2021
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38, and NSG prior to 1.33 patch 4.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zyxel vpn orchestrator

zyxel zld

zyxel nsg_firmware

zyxel nsg_firmware 1.33

zyxel usg_flex_firmware -