PT-2019-4110 · Zyxel · Zyxel Gs1900

Jasper Lievisse Adriaanse

·

Published

2019-11-14

·

Updated

2019-11-21

·

CVE-2019-15799

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0
Description An issue allows user accounts with non-admin level privileges to have the same level of privileged access as administrators when connecting to the device via SSH. This enables normal users to obtain the administrative password by running the tech-support command via the CLI, which contains the encrypted passwords for all users on the device. These passwords can be decrypted as they are encrypted using well-known and static parameters, allowing the original passwords, including the administrator password, to be obtained.
Recommendations For Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0, update the firmware to version 2.50(AAHH.0)C0 or later to resolve the issue. As a temporary workaround, consider restricting SSH access to only administrative accounts until the firmware can be updated.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04681
CVE-2019-15799

Affected Products

Zyxel Gs1900