CVE Published: 28/11/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: Zyxel |
Vendor: Zyxel |
Product: USG FLEX series firmware Status : PUBLISHED
CVE-2023-5960 Description
An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.37 and VPN series firmware versions 4.30 through 5.37 could allow an authenticated local attacker to access the system files on an affected device.
Metrics
CVSS Version: 3.1 |
Base Score: 5.5 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N