« Volver al listado

CVE-2007-4316

Estado: ModificadaMedia (4.3)—

The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device has a certain default password, which allows remote attackers to perform administrative actions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-4316",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-08-13T21:17:00.000",
  "references": [
    {
      "url": "http://osvdb.org/37669",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/26381",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/3002",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.louhi.fi/advisory/zyxel_070810.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/476031/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35914",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/37669",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/26381",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/3002",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.louhi.fi/advisory/zyxel_070810.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/476031/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35914",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device has a certain default password, which allows remote attackers to perform administrative actions."
    },
    {
      "lang": "es",
      "value": "La interfaz de administración en el software empotrado (firmware) ZyNOS 3.62 (WK.6) en el dispositivo Zyxel Zywall 2 tiene una contraseña por defecto fija, lo cual permite a atacantes remotos llevar a cabo acciones administrativas."
    }
  ],
  "lastModified": "2026-06-16T22:43:47.987",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:zynos:3.62:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E57C45D-9E5D-4638-AA28-CC7ABB9E5A4F"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:zywall_2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08C561C2-F462-4F79-9D79-AE5E634B5324"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "This is a cross-site scripting vulnerability that exists in the management console interface.",
  "sourceIdentifier": "cve@mitre.org"
}