Vulnerability Description
The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Pmg5318-B20A Firmware | v100aanc0b5 |
References
- http://www.securitytracker.com/id/1034553
- https://www.kb.cert.org/vuls/id/870744Third Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/BLUU-9ZQU2RThird Party AdvisoryUS Government Resource
- http://www.securitytracker.com/id/1034553
- https://www.kb.cert.org/vuls/id/870744Third Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/BLUU-9ZQU2RThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2015-6019?
CVE-2015-6019 is a vulnerability with a CVSS score of 8.5 (HIGH). The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote attackers to bypass intended access restrictions by ...
How severe is CVE-2015-6019?
CVE-2015-6019 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-6019?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Pmg5318-B20A Firmware.