CVE-2020-29299
Summary
| CVE | CVE-2020-29299 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-27 06:15:00 UTC |
| Updated | 2021-01-05 14:47:00 UTC |
| Description | Certain Zyxel products allow command injection by an admin via an input string to chg_exp_pwd during a password-change action. This affects VPN On-premise before ZLD V4.39 week38, VPN Orchestrator before SD-OS V10.03 week32, USG before ZLD V4.39 week38, USG FLEX before ZLD V4.55 week38, ATP before ZLD V4.55 week38, and NSG before 1.33 patch 4. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Zyxel | Atp | - | All | All | All |
| Hardware | Zyxel | Atp | - | All | All | All |
| Hardware | Zyxel | Nsg | - | All | All | All |
| Hardware | Zyxel | Nsg | - | All | All | All |
| Operating System | Zyxel | Nsg Firmware | All | All | All | All |
| Operating System | Zyxel | Nsg Firmware | 1.33 | - | All | All |
| Operating System | Zyxel | Nsg Firmware | 1.33 | patch1 | All | All |
| Operating System | Zyxel | Nsg Firmware | All | All | All | All |
| Operating System | Zyxel | Nsg Firmware | 1.33 | - | All | All |
| Operating System | Zyxel | Nsg Firmware | 1.33 | patch1 | All | All |
| Hardware | Zyxel | Usg Flex | - | All | All | All |
| Hardware | Zyxel | Usg Flex | - | All | All | All |
| Operating System | Zyxel | Usg Flex Firmware | - | All | All | All |
| Operating System | Zyxel | Usg Flex Firmware | - | All | All | All |
| Operating System | Zyxel | Vpn Orchestrator | All | All | All | All |
| Operating System | Zyxel | Vpn Orchestrator | All | All | All | All |
| Operating System | Zyxel | Zld | All | All | All | All |
| Operating System | Zyxel | Zld | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zyxel security advisory for command injection vulnerability of firewalls | Zyxel | MISC | www.zyxel.com | Vendor Advisory |
| Security Advisories | Zyxel | MISC | www.zyxel.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.