CVE-2020-13365
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and V5.21(ABAG.3)C0; NSA325 v2_V4.81(AALS.0)C0 and V4.81(AAAJ.1)C0; NSA310 4.22(AFK.0)C0 and 4.22(AFK.1)C0; NAS326 V5.21(AAZF.8)C0, V5.11(AAZF.4)C0, V5.11(AAZF.2)C0, and V5.11(AAZF.3)C0; NSA310S V4.75(AALH.2)C0; NSA320S V4.75(AANV.2)C0 and V4.75(AANV.1)C0; NSA221 V4.41(AFM.1)C0; and NAS540 V5.21(AATB.5)C0 and V5.21(AATB.3)C0.
Determinados productos Zyxel tienen un binario accesible localmente que permite a un usuario no root generar una contraseña para una cuenta de usuario no documentada que puede ser usada para una sesión de TELNET como root. Esto afecta a NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, y V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, y V5.21(ABAG.3)C0; NSA325 v2_V4.81(AALS.0)C0 y V4.81(AAAJ.1)C0; NSA310 4.22(AFK.0)C0 y 4.22(AFK.1)C0; NAS326 V5.21(AAZF.8)C0, V5.11(AAZF.4)C0, V5.11(AAZF.2)C0, y V5.11(AAZF.3)C0; NSA310S V4.75(AALH.2)C0; NSA320S V4.75(AANV.2)C0 y V4.75(AANV.1)C0; NSA221 V4.41(AFM.1)C0; y NAS540 V5.21(AATB.5)C0 y V5.21(AATB.3)C0
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-05-21 CVE Reserved
- 2020-08-06 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zyxel Search vendor "Zyxel" | Nas326 Firmware Search vendor "Zyxel" for product "Nas326 Firmware" | < v5.21\(aazf.9\)c0 Search vendor "Zyxel" for product "Nas326 Firmware" and version " < v5.21\(aazf.9\)c0" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Nas326 Search vendor "Zyxel" for product "Nas326" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Nas520 Firmware Search vendor "Zyxel" for product "Nas520 Firmware" | < v5.21\(aasz.5\)c0 Search vendor "Zyxel" for product "Nas520 Firmware" and version " < v5.21\(aasz.5\)c0" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Nas520 Search vendor "Zyxel" for product "Nas520" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Nas540 Firmware Search vendor "Zyxel" for product "Nas540 Firmware" | < v5.21\(aatb.6\)c0 Search vendor "Zyxel" for product "Nas540 Firmware" and version " < v5.21\(aatb.6\)c0" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Nas540 Search vendor "Zyxel" for product "Nas540" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Nas542 Firmware Search vendor "Zyxel" for product "Nas542 Firmware" | < v5.21\(abag.6\)c0 Search vendor "Zyxel" for product "Nas542 Firmware" and version " < v5.21\(abag.6\)c0" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Nas542 Search vendor "Zyxel" for product "Nas542" | - | - |
Safe
|