← Back

CVE-2022-40603

nvd nist
Published: Dec 6, 2022Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A cross-site scripting (XSS) vulnerability in the CGI program of Zyxel ZyWALL/USG series firmware versions 4.30 through 4.72, VPN series firmware versions 4.30 through 5.31, USG FLEX series firmware versions 4.50 through 5.31, and ATP series firmware versions 4.32 through 5.31, which could allow an attacker to trick a user into visiting a crafted URL with the XSS payload. Then, the attacker could gain access to some browser-based information if the malicious script is executed on the victim’s browser.

Affected (19)

19 products
Atp800 Firmware
Atp700 Firmware
Atp500 Firmware
Atp200 Firmware
Atp100 Firmware
Atp100w Firmware
Usg Flex 100w Firmware
Usg Flex 200 Firmware
Usg Flex 500 Firmware
Usg Flex 700 Firmware
Usg Flex 50w Firmware
Vpn1000 Firmware
Vpn300 Firmware
Vpn100 Firmware
Vpn50 Firmware
Usg40 Firmware
Usg40w Firmware
Usg60 Firmware
Usg60w Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.32 to 5.31
Running on/withPlatform Versions
Zyxel
Atp800
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.32 to 5.31
Running on/withPlatform Versions
Zyxel
Atp700
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.32 to 5.31
Running on/withPlatform Versions
Zyxel
Atp500
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.32 to 5.31
Running on/withPlatform Versions
Zyxel
Atp200
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.32 to 5.31
Running on/withPlatform Versions
Zyxel
Atp100
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.32 to 5.31
Running on/withPlatform Versions
Zyxel
Atp100w
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.50 to 5.31
Running on/withPlatform Versions
Zyxel
Usg Flex 100w
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.50 to 5.31
Running on/withPlatform Versions
Zyxel
Usg Flex 200
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.50 to 5.31
Running on/withPlatform Versions
Zyxel
Usg Flex 500
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.50 to 5.31
Running on/withPlatform Versions
Zyxel
Usg Flex 700
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.50 to 5.31
Running on/withPlatform Versions
Zyxel
Usg Flex 50w
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.30 to 5.31
Running on/withPlatform Versions
Zyxel
Vpn1000
All versions
Configuration M
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.30 to 5.31
Running on/withPlatform Versions
Zyxel
Vpn300
All versions
Configuration N
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.30 to 5.31
Running on/withPlatform Versions
Zyxel
Vpn100
All versions
Configuration O
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.30 to 5.31
Running on/withPlatform Versions
Zyxel
Vpn50
All versions
Configuration P
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.30 to 4.72
Running on/withPlatform Versions
Zyxel
Usg40
All versions
Configuration Q
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.30 to 4.72
Running on/withPlatform Versions
Zyxel
Usg40w
All versions
Configuration R
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.30 to 4.72
Running on/withPlatform Versions
Zyxel
Usg60
All versions
Configuration S
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.30 to 4.72
Running on/withPlatform Versions
Zyxel
Usg60w
All versions

Timeline

No history available yet.