ZyXEL ZyWALL USG Appliances Web Interface Security Bypass Vulnerability
BID:47706
Info
ZyXEL ZyWALL USG Appliances Web Interface Security Bypass Vulnerability
| Bugtraq ID: | 47706 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 04 2011 12:00AM |
| Updated: | May 04 2011 12:00AM |
| Credit: | RedTeam |
| Vulnerable: |
ZyXEL ZYWall USG-50 ZyXEL ZYWall USG-300 ZyXEL ZYWall USG-20W ZyXEL ZYWall USG-2000 ZyXEL ZYWall USG-200 ZyXEL ZYWall USG-20 ZyXEL ZYWall USG-1050 ZyXEL ZYWall USG-1000 ZyXEL ZYWall USG-100 |
| Not Vulnerable: | |
Discussion
ZyXEL ZyWALL USG Appliances Web Interface Security Bypass Vulnerability
ZyXEL ZyWALL USG Appliances are prone to a security-bypass vulnerability.
Remote attackers can exploit this issue to bypass security restrictions, access certain administrative functions, alter configurations, or trigger a denial-of-service condition.
ZyXEL ZyWALL USG Appliances are prone to a security-bypass vulnerability.
Remote attackers can exploit this issue to bypass security restrictions, access certain administrative functions, alter configurations, or trigger a denial-of-service condition.
Exploit / POC
ZyXEL ZyWALL USG Appliances Web Interface Security Bypass Vulnerability
An attacker can exploit this issue by using readily available network utilities.
An attacker can exploit this issue by using readily available network utilities.
Solution / Fix
ZyXEL ZyWALL USG Appliances Web Interface Security Bypass Vulnerability
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed; however, Symantec has not confirmed this. Please contact the vendor for more information.
References
ZyXEL ZyWALL USG Appliances Web Interface Security Bypass Vulnerability
References:
References: