V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2019-12583
CVE
Critical

Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate gues…

CVSS
9.1
Critical
EPSS
0.44
p98
Published
2019-01-01
Updated
2019-01-01
Description

Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guest accounts by directly accessing the account generator. This can lead to unauthorised network access or Denial of Service.

Tags · CWE
Pre-auth
CWE-425
CAPEC-87
CAPEC-127
CAPEC-143
CAPEC-144
CAPEC-668
Affected products
Uag2100_firmwareUag4100_firmwareUag5100_firmwareUsg1100_firmwareUsg110_firmwareUsg1900_firmwareUsg210_firmwareUsg2200-vpn_firmwareUsg310_firmwareZywall_1100_firmwareZywall_110_firmwareZywall_310_firmwareZywall_vpn100_firmwareZywall_vpn300_firmware
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.439 · p98
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-127 · CWE-425
└ via CAPEC-668 · CWE-425
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
uag2100_firmware*Tracked
uag4100_firmware*Tracked
uag5100_firmware*Tracked
usg1100_firmware*Tracked
usg110_firmware*Tracked
usg1900_firmware*Tracked
usg210_firmware*Tracked
usg2200-vpn_firmware*Tracked
usg310_firmware*Tracked
zywall_1100_firmware*Tracked
zywall_110_firmware*Tracked
zywall_310_firmware*Tracked
zywall_vpn100_firmware*Tracked
zywall_vpn300_firmware*Tracked
Source databases
CVE