Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-9955


On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.


Published

2019-04-22T20:29:00.447

Last Modified

2024-11-21T04:52:39.943

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zyxel atp200_firmware 4.31 Yes
Hardware zyxel atp200 - No
Operating System zyxel atp500_firmware 4.31 Yes
Hardware zyxel atp500 - No
Operating System zyxel atp800_firmware 4.31 Yes
Hardware zyxel atp800 - No
Operating System zyxel usg20-vpn_firmware 4.31 Yes
Hardware zyxel usg20-vpn - No
Operating System zyxel usg20w-vpn_firmware 4.31 Yes
Hardware zyxel usg20w-vpn - No
Operating System zyxel usg40_firmware 4.31 Yes
Hardware zyxel usg40 - No
Operating System zyxel usg40w_firmware 4.31 Yes
Hardware zyxel usg40w - No
Operating System zyxel usg60_firmware 4.31 Yes
Hardware zyxel usg60 - No
Operating System zyxel usg60w_firmware 4.31 Yes
Hardware zyxel usg60w - No
Operating System zyxel usg110_firmware 4.31 Yes
Hardware zyxel usg110 - No
Operating System zyxel usg210_firmware 4.31 Yes
Hardware zyxel usg210 - No
Operating System zyxel usg310_firmware 4.31 Yes
Hardware zyxel usg310 - No
Operating System zyxel usg1100_firmware 4.31 Yes
Hardware zyxel usg1100 - No
Operating System zyxel usg1900_firmware 4.31 Yes
Hardware zyxel usg1900 - No
Operating System zyxel usg2200-vpn_firmware 4.31 Yes
Hardware zyxel usg2200-vpn - No
Operating System zyxel zywall_110_firmware 4.31 Yes
Hardware zyxel zywall_110 - No
Operating System zyxel zywall_310_firmware 4.31 Yes
Hardware zyxel zywall_310 - No
Operating System zyxel zywall_1100_firmware 4.31 Yes
Hardware zyxel zywall_1100 - No
Operating System zyxel vpn50_firmware - Yes
Hardware zyxel vpn50 - No
Operating System zyxel vpn100_firmware - Yes
Hardware zyxel vpn100 - No
Operating System zyxel vpn300_firmware - Yes
Hardware zyxel vpn300 - No

References