CVE Vulnerabilities

CVE-2023-35140

Improper Privilege Management

Published: Nov 07, 2023 | Modified: Nov 14, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The improper privilege management vulnerability in the Zyxel GS1900-24EP switch firmware version V2.70(ABTO.5) could allow an authenticated local user with read-only access to modify system settings on a vulnerable device.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Gs1900-48hpv2_firmware Zyxel * 2.70(abtq.5) (including)

Potential Mitigations

References