Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-35140


The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.


Published

2023-11-07T05:15:12.077

Last Modified

2024-11-21T08:08:01.030

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System zyxel gs1900-48hpv2_firmware ≤ 2.70\(abtq.5\) Yes
Hardware zyxel gs1900-48hpv2 - No
Operating System zyxel gs1900-48_firmware ≤ 2.70\(aahn.5\) Yes
Hardware zyxel gs1900-48 - No
Operating System zyxel gs1900-24hpv2_firmware ≤ 2.70\(abtp.5\) Yes
Hardware zyxel gs1900-24hpv2 - No
Operating System zyxel gs1900-24ep_firmware ≤ 2.70\(abto.5\) Yes
Hardware zyxel gs1900-24ep - No
Operating System zyxel gs1900-24e_firmware ≤ 2.70\(aahk.5\) Yes
Hardware zyxel gs1900-24e - No
Operating System zyxel gs1900-24_firmware ≤ 2.70\(aahl.5\) Yes
Hardware zyxel gs1900-24 - No
Operating System zyxel gs1900-16_firmware ≤ 2.70\(aahj.5\) Yes
Hardware zyxel gs1900-16 - No
Operating System zyxel gs1900-10hp_firmware ≤ 2.70\(aazi.5\) Yes
Hardware zyxel gs1900-10hp - No
Operating System zyxel gs1900-8hp_firmware ≤ 2.70\(aahi.5\) Yes
Hardware zyxel gs1900-8hp - No
Operating System zyxel gs1900-8_firmware ≤ 2.70\(aahh.5\) Yes
Hardware zyxel gs1900-8 - No

References