Vulnerability Description
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Zywall 1050 Firmware | - |
| Zyxel | Zywall 1050 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.org/0803-exploits/ZyWALL.pdfBroken Link
- http://secunia.com/advisories/29237Broken LinkVendor Advisory
- http://www.secumania.org/exploits/remote/zyxel-zywall-quagga_zebra-%28default-paBroken LinkURL Repurposed
- http://www.securityfocus.com/bid/28184Broken LinkThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2008/0990/referencesBroken LinkVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41424Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/5289Third Party AdvisoryVDB Entry
- http://packetstormsecurity.org/0803-exploits/ZyWALL.pdfBroken Link
- http://secunia.com/advisories/29237Broken LinkVendor Advisory
- http://www.secumania.org/exploits/remote/zyxel-zywall-quagga_zebra-%28default-paBroken LinkURL Repurposed
- http://www.securityfocus.com/bid/28184Broken LinkThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2008/0990/referencesBroken LinkVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41424Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/5289Third Party AdvisoryVDB Entry
FAQ
What is CVE-2008-1160?
CVE-2008-1160 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.
How severe is CVE-2008-1160?
CVE-2008-1160 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2008-1160?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Zywall 1050 Firmware, Zyxel Zywall 1050.