PT-2022-3215 · Zyxel · Zyxel Gs1200

Published

2022-06-07

·

Updated

2023-06-27

·

CVE-2022-0823

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zyxel GS1200 series switches (affected versions not specified)
Description The issue is related to an improper control of interaction frequency, which could allow a local attacker to guess the password by using a timing side-channel attack. This vulnerability is also associated with the disclosure of information due to inconsistency, potentially allowing an attacker to gain unauthorized access to protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Side Channel Attack

Weakness Enumeration

Related Identifiers

BDU:2022-03913
CVE-2022-0823

Affected Products

Zyxel Gs1200