← Back

CVE-2019-9955

Published: Apr 22, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.

Affected Products (21)

CPE details will appear after the next data sync.
21 products
Atp200 Firmware
Atp500 Firmware
Atp800 Firmware
Usg1100 Firmware
Usg110 Firmware
Usg1900 Firmware
Usg20 Vpn Firmware
Usg20w Vpn Firmware
Usg210 Firmware
Usg2200 Vpn Firmware
Usg310 Firmware
Usg40 Firmware
Usg40w Firmware
Usg60 Firmware
Usg60w Firmware
Vpn100 Firmware
Vpn300 Firmware
Vpn50 Firmware
Zywall 1100 Firmware
Zywall 110 Firmware
Zywall 310 Firmware

References (10)

Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.