V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2020-29583
CVE
Critical KEVConfirmedExploit available

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this ac…

CVSS
9.8
Critical
EPSS
0.94
p99
Published
2020-01-01
Updated
2021-11-03
Description

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.

Tags · CWE
KEVPre-auth
CWE-522
CAPEC-50
CAPEC-102
CAPEC-474
CAPEC-509
CAPEC-551
CAPEC-555
CAPEC-560
CAPEC-561
CAPEC-600
CAPEC-644
CAPEC-645
CAPEC-652
CAPEC-653
Affected products
Atp100_firmwareAtp100w_firmwareAtp200_firmwareAtp500_firmwareAtp700_firmwareAtp800_firmwareUsg1100_firmwareUsg110_firmwareUsg1900_firmwareUsg20-vpn_firmwareUsg20w-vpn_firmwareUsg210_firmwareUsg2200_firmwareUsg310_firmwareUsg40_firmwareUsg40w_firmwareUsg60_firmwareUsg60w_firmwareUsg_flex_100_firmwareUsg_flex_100w_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2020-01-01
Published
2021-11-03
Added to KEV
2021-11-03
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.943 · p99
Known exploited (KEV)
Yes
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-555 · CWE-522
└ via CAPEC-561 · CWE-522
└ via CAPEC-560 · CWE-522
└ via CAPEC-600 · CWE-522
└ via CAPEC-555 · CWE-522
└ via CAPEC-555 · CWE-522
└ via CAPEC-551 · CWE-522
└ via CAPEC-644 · CWE-522
└ via CAPEC-645 · CWE-522
└ via CAPEC-474 · CWE-522
└ via CAPEC-652 · CWE-522
└ via CAPEC-509 · CWE-522
Known exploits — Сканер-ВС
CVE-2020-29583
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
Affected software
ProductVendorStatus
atp100_firmware*Exploited
atp100w_firmware*Exploited
atp200_firmware*Exploited
atp500_firmware*Exploited
atp700_firmware*Exploited
atp800_firmware*Exploited
usg1100_firmware*Exploited
usg110_firmware*Exploited
usg1900_firmware*Exploited
usg20-vpn_firmware*Exploited
usg20w-vpn_firmware*Exploited
usg210_firmware*Exploited
usg2200_firmware*Exploited
usg310_firmware*Exploited
usg40_firmware*Exploited
usg40w_firmware*Exploited
usg60_firmware*Exploited
usg60w_firmware*Exploited
usg_flex_100_firmware*Exploited
usg_flex_100w_firmware*Exploited
Source databases
CVE
Related vulnerabilities