CVE-2020-29583

Scores

EPSS

0.942high94.2%
0%20%40%60%80%100%

Percentile: 94.2%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Description

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-522

Related Vulnerabilities

Exploits

Exploit ID: CVE-2020-29583

Source: github-poc

URL: https://github.com/ruppde/scan_CVE-2020-29583

Vulnerable Software (30)

Type: Configuration

Vendor: zyxel

Product: atp100_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:atp100_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: zyxel

Product: atp100w_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:atp100w_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

Type: Configuration

Vendor: zyxel

Product: atp200_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:atp200_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: zyxel

Product: atp500_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:atp500_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: zyxel

Product: atp700_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:atp700_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: zyxel

Product: atp800_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:atp800_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: zyxel

Product: usg1100_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg1100_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

Type: Configuration

Vendor: zyxel

Product: usg110_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg110_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: zyxel

Product: usg1900_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg1900_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

Type: Configuration

Vendor: zyxel

Product: usg20-vpn_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:zyxel:usg20-vpn_firmware:4.60:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": ...

Source: nvd