CVE-2019-15804 Information
Feb 14, 2021
cve
Description
An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. By sending a signal to the CLI process undocumented functionality is triggered. Specifically a menu can be triggered by sending the SIGQUIT signal to the CLI application (e.g. through CTRL+\ via SSH). The access control check for this menu does work and prohibits accessing the menu which contains \Password recovery for specific user\ options. The menu is believed to be accessible using a serial console.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Reference
https://jasper.la/exploring-zyxel-gs1900-firmware-with-ghidra.html https://www.zyxel.com/support/gs1900-switch-vulnerabilities.shtml
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
7.5
Share on: