PT-2019-4110 · Zyxel · Zyxel Gs1900
Jasper Lievisse Adriaanse
·
Published
2019-11-14
·
Updated
2019-11-21
·
CVE-2019-15799
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0
Description
An issue allows user accounts with non-admin level privileges to have the same level of privileged access as administrators when connecting to the device via SSH. This enables normal users to obtain the administrative password by running the
tech-support command via the CLI, which contains the encrypted passwords for all users on the device. These passwords can be decrypted as they are encrypted using well-known and static parameters, allowing the original passwords, including the administrator password, to be obtained.Recommendations
For Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0, update the firmware to version 2.50(AAHH.0)C0 or later to resolve the issue. As a temporary workaround, consider restricting SSH access to only administrative accounts until the firmware can be updated.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zyxel Gs1900