PT-2019-11949 · Zyxel · Zyxel Nas326
Maxwell Dulin
·
Published
2019-04-09
·
Updated
2020-08-24
·
CVE-2019-10630
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zyxel NAS 326 versions through 5.21
Description
A plaintext password issue allows an elevated privileged user to obtain the admin password of the device.
Recommendations
For versions through 5.21, update to a version that contains a fix for this issue to prevent elevated privileged users from accessing the admin password.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Nas326