CVE-2022-0734

MEDIUMCVSS 6.1/10EPSS 8.36%

Last modified

CVE-2022-0734 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to obtain some information stored in the user's browser, such as cookies or session tokens, via a malicious script.. EPSS estimates a 8.36% chance of exploitation in the next 30 days.

Description

A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to obtain some information stored in the user's browser, such as cookies or session tokens, via a malicious script.

Metrics

CVSS 3.1
6.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Probability
8.36%

94.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ZyxelVpn100 Firmware>= 4.35, <= 5.20
ZyxelVpn1000 Firmware>= 4.35, <= 5.20
ZyxelVpn300 Firmware>= 4.35, <= 5.20
ZyxelVpn50 Firmware>= 4.35, <= 5.20
ZyxelAtp100 Firmware>= 4.35, <= 5.20
ZyxelAtp100w Firmware>= 4.35, <= 5.20
ZyxelAtp200 Firmware>= 4.35, <= 5.20
ZyxelAtp500 Firmware>= 4.35, <= 5.20
ZyxelAtp700 Firmware>= 4.35, <= 5.20
ZyxelAtp800 Firmware>= 4.35, <= 5.20
ZyxelUsg 110 Firmware>= 4.35, <= 4.70
ZyxelUsg 1100 Firmware>= 4.35, <= 4.70
ZyxelUsg 1900 Firmware>= 4.35, <= 4.70
ZyxelUsg 20w Firmware>= 4.35, <= 4.70
ZyxelUsg 20w-Vpn Firmware>= 4.35, <= 4.70
ZyxelUsg 2200-Vpn Firmware>= 4.35, <= 4.70
ZyxelUsg 310 Firmware>= 4.35, <= 4.70
ZyxelUsg 40 Firmware>= 4.35, <= 4.70
ZyxelUsg 40w Firmware>= 4.35, <= 4.70
ZyxelUsg 60 Firmware>= 4.35, <= 4.70
ZyxelUsg 60w Firmware>= 4.35, <= 4.70
ZyxelUsg Flex 100 Firmware>= 4.50, <= 5.20
ZyxelUsg Flex 100w Firmware>= 4.50, <= 5.20
ZyxelUsg Flex 200 Firmware>= 4.50, <= 5.20
ZyxelUsg Flex 500 Firmware>= 4.50, <= 5.20
ZyxelUsg Flex 700 Firmware>= 4.50, <= 5.20
ZyxelUsg200 Firmware>= 4.35, <= 4.70
ZyxelUsg20 Firmware>= 4.35, <= 4.70
ZyxelUsg210 Firmware>= 4.35, <= 4.70
ZyxelUsg2200 Firmware>= 4.35, <= 4.70
ZyxelUsg300 Firmware>= 4.35, <= 4.70
ZyxelUsg310 Firmware>= 4.35, <= 4.70

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-0734?
A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to obtain some information stored in the user's browser, such as cookies or session tokens, via a malicious script.
How severe is CVE-2022-0734?
CVE-2022-0734 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 8.36% probability of exploitation in the next 30 days.
How do I fix CVE-2022-0734?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-0734?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST