CVE-2022-0823
6.2
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.5 / Impact: 3.6
Source: NVD
Description
An improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker to guess the password by using a timing side-channel attack.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00\(abkm.1\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Gs1200 5 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00\(abkn.1\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Gs1200 5hp | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00\(abme.1\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Gs1200 8 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00\(abmf.1\) |
| Running on/with | Platform Versions |
|---|---|
Zyxel Gs1200 8hp | All versions |
References (2)
Source: security@zyxel.com.tw
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.