CVE-2019-9955

UnknownEPSS 20.95%

Last modified

CVE-2019-9955 is a vulnerability of currently unknown severity. On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.. EPSS estimates a 20.95% chance of exploitation in the next 30 days.

Description

On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.

Metrics

EPSS Probability
20.95%

97.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ZyxelAtp200 Firmware4.31
ZyxelAtp500 Firmware4.31
ZyxelAtp800 Firmware4.31
ZyxelUsg20-Vpn Firmware4.31
ZyxelUsg20w-Vpn Firmware4.31
ZyxelUsg40 Firmware4.31
ZyxelUsg40w Firmware4.31
ZyxelUsg60 Firmware4.31
ZyxelUsg60w Firmware4.31
ZyxelUsg110 Firmware4.31
ZyxelUsg210 Firmware4.31
ZyxelUsg310 Firmware4.31
ZyxelUsg1100 Firmware4.31
ZyxelUsg1900 Firmware4.31
ZyxelUsg2200-Vpn Firmware4.31
ZyxelZywall 110 Firmware4.31
ZyxelZywall 310 Firmware4.31
ZyxelZywall 1100 Firmware4.31
ZyxelVpn50 FirmwareAll versions
ZyxelVpn100 FirmwareAll versions
ZyxelVpn300 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-9955?
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, USG1900, USG2200-VPN, ZyWALL 110, ZyWALL 310, ZyWALL 1100 devices, the security firewall login page is vulnerable to Reflected XSS via the unsanitized 'mp_idx' parameter.
How severe is CVE-2019-9955?
Severity scoring for CVE-2019-9955 is pending analysis. The EPSS model estimates a 20.95% probability of exploitation in the next 30 days.
How do I fix CVE-2019-9955?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-9955?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST