CVE-2023-5797
Severity
5.5MEDIUM
EPSS
0.1%
top 84.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 28
Description
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, NWA50AX firmware version 6.29(ABYW.2), WAC500 firmware version 6.65(ABVS.1), WAX300H firmware version 6.60(ACHF.1), and WBE660S firmware version 6.65(…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages29 packages
🔴Vulnerability Details
2CVEList▶
CVE-2023-5797: An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4↗2023-11-28
GHSA▶
GHSA-x5q7-jv6g-p5gv: An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4↗2023-11-28