Author: Angelo Barbosa

CVE-2023-35136 | Zyxel ATP/USG FLEX/USG FLEX 50/USG20-VPN/VPN Configuration File information disclosure

A vulnerability classified as problematic was found in Zyxel ATP, USG FLEX, USG FLEX 50, USG20-VPN and VPN. This vulnerability affects unknown code of the component Configuration File Handler. The manipulation leads to information disclosure. This vulnerability was named CVE-2023-35136. Local access is required to approach this attack. There is no exploit...

Read More

CVE-2023-5960 | Zyxel USG FLEX/VPN Hotspot privileges management

A vulnerability was found in Zyxel USG FLEX and VPN. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Hotspot. The manipulation leads to improper privilege management. This vulnerability is handled as CVE-2023-5960. The attack needs to be approached locally. There is no exploit...

Read More

CVE-2023-5797 | Zyxel ATP Debug CLI Command privileges management

A vulnerability was found in Zyxel ATP, USG FLEX, USG FLEX 50, USG20-VPN, VPN, NWA50AX, WAC500, WAX300H and WBE660S. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Debug CLI Command Handler. The manipulation leads to improper privilege management. This vulnerability is known as CVE-2023-5797. It is possible to launch the attack on the local host. There is no exploit...

Read More

CVE-2023-48713 | knative serving up to 0.38.x Autoscaler /metrics resource consumption (GHSA-qmvj-4qr9-v547)

A vulnerability was found in knative serving up to 0.38.x. It has been classified as problematic. Affected is an unknown function of the file /metrics of the component Autoscaler. The manipulation leads to resource consumption. This vulnerability is traded as CVE-2023-48713. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More