CVE-2022-45853
30.05.2023, 11:15
The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3)and the GS1900-8HP firmware versionV2.70(AAHI.3) could allow an authenticated, local attacker with administrator privileges to execute some system commands as 'root' on a vulnerable device via SSH.Enginsight
Vendor | Product | Version |
---|---|---|
zyxel | gs1900-8_firmware | 2.70\(aahh.3\) |
zyxel | gs1900-8hp_firmware | 2.70\(aahi.3\) |
zyxel | gs1900-10hp_firmware | 2.70\(aazi.3\) |
zyxel | gs1900-16_firmware | 2.70\(aahj.3\) |
zyxel | gs1900-24_firmware | 2.70\(aahl.3\) |
zyxel | gs1900-24e_firmware | 2.70\(aahk.3\) |
zyxel | gs1900-24ep_firmware | 2.70\(abto.3\) |
zyxel | gs1900-24hpv2_firmware | 2.70\(abtp.3\) |
zyxel | gs1900-48_firmware | 2.70\(aahn.3\) |
zyxel | gs1900-48hpv2_firmware | 2.70\(abtq.3\) |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
- CWE-276 - Incorrect Default PermissionsDuring installation, installed file permissions are set to allow anyone to modify those files.
References