CVE-2020-29583

Scores

EPSS

0.944high94.4%
0%20%40%60%80%100%

Percentile: 94.4%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Description

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-522

Related Vulnerabilities

Exploits

Exploit ID: CVE-2020-29583

Source: github-poc

URL: https://github.com/ruppde/scan_CVE-2020-29583

Vulnerable Software (30)

Type: Configuration

Vendor: *

Product: atp100_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:atp100_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: atp100w_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:atp100w_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

Type: Configuration

Vendor: *

Product: atp200_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:atp200_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: atp500_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:atp500_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: atp700_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:atp700_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: atp800_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:atp800_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: usg1100_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg1100_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

Type: Configuration

Vendor: *

Product: usg110_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg110_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: usg1900_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg1900_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

Type: Configuration

Vendor: *

Product: usg20-vpn_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg20-vpn_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": ...

Source: nvd

Type: Configuration

Vendor: *

Product: usg20w-vpn_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg20w-vpn_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator":...

Source: nvd

Type: Configuration

Vendor: *

Product: usg210_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg210_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: usg2200_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg2200_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

Type: Configuration

Vendor: *

Product: usg310_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg310_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: usg40_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg40_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR"...

Source: nvd

Type: Configuration

Vendor: *

Product: usg40w_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg40w_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: usg60_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg60_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR"...

Source: nvd

Type: Configuration

Vendor: *

Product: usg60w_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg60w_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: usg_flex_100_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg_flex_100_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator...

Source: nvd

Type: Configuration

Vendor: *

Product: usg_flex_100w_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg_flex_100w_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operato...

Source: nvd