PT-2020-17137 · Zyxel · Zyxel Vpn Orchestrator+5

Published

2020-12-27

·

Updated

2021-01-05

·

CVE-2020-29299

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel VPN On-premise versions prior to ZLD V4.39 week38 Zyxel VPN Orchestrator versions prior to SD-OS V10.03 week32 Zyxel USG versions prior to ZLD V4.39 week38 Zyxel USG FLEX versions prior to ZLD V4.55 week38 Zyxel ATP versions prior to ZLD V4.55 week38 Zyxel NSG versions prior to 1.33 patch 4
Description Certain Zyxel products allow command injection by an admin via an input string to chg exp pwd during a password-change action.
Recommendations For Zyxel VPN On-premise versions prior to ZLD V4.39 week38, update to ZLD V4.39 week38 or later. For Zyxel VPN Orchestrator versions prior to SD-OS V10.03 week32, update to SD-OS V10.03 week32 or later. For Zyxel USG versions prior to ZLD V4.39 week38, update to ZLD V4.39 week38 or later. For Zyxel USG FLEX versions prior to ZLD V4.55 week38, update to ZLD V4.55 week38 or later. For Zyxel ATP versions prior to ZLD V4.55 week38, update to ZLD V4.55 week38 or later. For Zyxel NSG versions prior to 1.33 patch 4, update to 1.33 patch 4 or later. As a temporary workaround, consider restricting access to the chg exp pwd function until a patch is available.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29299

Affected Products

Zyxel Atp
Zyxel Nsg
Zyxel Usg
Zyxel Usg Flex
Zyxel Vpn On-Premise
Zyxel Vpn Orchestrator