Логотип exploitDog
bind:CVE-2019-15799
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-15799

Количество 3

Количество 3

nvd логотип

CVE-2019-15799

около 6 лет назад

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, when given non-admin level privileges, have the same level of privileged access as administrators when connecting to the device via SSH (while their permissions via the web interface are in fact restricted). This allows normal users to obtain the administrative password by running the tech-support command via the CLI: this contains the encrypted passwords for all users on the device. As these passwords are encrypted using well-known and static parameters, they can be decrypted and the original passwords (including the administrator password) can be obtained.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-fvpf-4m7h-jg3p

больше 3 лет назад

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, when given non-admin level privileges, have the same level of privileged access as administrators when connecting to the device via SSH (while their permissions via the web interface are in fact restricted). This allows normal users to obtain the administrative password by running the tech-support command via the CLI: this contains the encrypted passwords for all users on the device. As these passwords are encrypted using well-known and static parameters, they can be decrypted and the original passwords (including the administrator password) can be obtained.

EPSS: Низкий
fstec логотип

BDU:2019-04681

около 6 лет назад

Уязвимость микропрограммного обеспечения маршрутизаторов Zyxel серии GS1900, связанная с наличием одинаковых привилегий доступа при подключении по ssh для пользовователей и администраторов, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-15799

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, when given non-admin level privileges, have the same level of privileged access as administrators when connecting to the device via SSH (while their permissions via the web interface are in fact restricted). This allows normal users to obtain the administrative password by running the tech-support command via the CLI: this contains the encrypted passwords for all users on the device. As these passwords are encrypted using well-known and static parameters, they can be decrypted and the original passwords (including the administrator password) can be obtained.

CVSS3: 8.8
0%
Низкий
около 6 лет назад
github логотип
GHSA-fvpf-4m7h-jg3p

An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the web interface of the device, when given non-admin level privileges, have the same level of privileged access as administrators when connecting to the device via SSH (while their permissions via the web interface are in fact restricted). This allows normal users to obtain the administrative password by running the tech-support command via the CLI: this contains the encrypted passwords for all users on the device. As these passwords are encrypted using well-known and static parameters, they can be decrypted and the original passwords (including the administrator password) can be obtained.

0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2019-04681

Уязвимость микропрограммного обеспечения маршрутизаторов Zyxel серии GS1900, связанная с наличием одинаковых привилегий доступа при подключении по ssh для пользовователей и администраторов, позволяющая нарушителю повысить свои привилегии

CVSS3: 8.8
0%
Низкий
около 6 лет назад

Уязвимостей на страницу