« Volver al listado

CVE-2023-5960

Estado: ModificadaMedia (5.5)—

An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series firmware versions 4.30 through 5.37 could allow an authenticated local attacker to access the system files on an affected device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-5960",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@zyxel.com.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@zyxel.com.tw",
      "affectedData": [
        {
          "vendor": "Zyxel",
          "product": "USG FLEX series firmware",
          "versions": [
            {
              "status": "affected",
              "version": "versions 4.50 through 5.37"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Zyxel",
          "product": "VPN series firmware",
          "versions": [
            {
              "status": "affected",
              "version": "versions 4.30 through 5.37"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-11-28T03:15:07.310",
  "references": [
    {
      "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-firewalls-and-aps",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@zyxel.com.tw"
    },
    {
      "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-firewalls-and-aps",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@zyxel.com.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series firmware versions 4.30 through 5.37 could allow an authenticated local attacker to access the system files on an affected device."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de administración de privilegios inadecuada en la función de punto de acceso de las versiones de firmware de la serie Zyxel USG FLEX 4.50 a 5.37 y las versiones de firmware de la serie VPN 4.30 a 5.37 podría permitir que un atacante local autenticado acceda a los archivos del sistema en un dispositivo afectado."
    }
  ],
  "lastModified": "2026-06-17T06:49:44.937",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "03FAEFC8-186B-4B52-869F-DA27224692C0",
              "versionEndIncluding": "5.37",
              "versionStartIncluding": "4.50"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2B30A4C0-9928-46AD-9210-C25656FB43FB"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_100w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D74ABA7E-AA78-4A13-A64E-C44021591B42"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F93B6A06-2951-46D2-A7E1-103D7318D612"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_50:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "646C1F07-B553-47B0-953B-DC7DE7FD0F8B"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_500:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "92C697A5-D1D3-4FF0-9C43-D27B18181958"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_50w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "110A1CA4-0170-4834-8281-0A3E14FC5584"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_700:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9D1396E3-731B-4D05-A3F8-F3ABB80D5C29"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "549A6FE1-25D6-4239-87B6-B729C098C625",
              "versionEndIncluding": "5.37",
              "versionStartIncluding": "4.30"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:vpn100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "81D90A7B-174F-40A1-8AF4-08B15B7BAC40"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:vpn1000:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EECD311A-4E96-4576-AADF-47291EDE3559"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:vpn300:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3C45C303-1A95-4245-B242-3AB9B9106CD4"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:vpn50:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9E3AC823-0ECA-42D8-8312-2FBE5914E4C0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@zyxel.com.tw"
}