MEDIUM · 5.8

CVE-2022-0734

A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series f...

Vulnerability Description

A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.35 through 5.20, and VPN series firmware versions 4.35 through 5.20, that could allow an attacker to obtain some information stored in the user's browser, such as cookies or session tokens, via a malicious script.

CVSS Score

5.8

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
ZyxelVpn100 Firmware>= 4.35, <= 5.20
ZyxelVpn100-
ZyxelVpn1000 Firmware>= 4.35, <= 5.20
ZyxelVpn1000-
ZyxelVpn300 Firmware>= 4.35, <= 5.20
ZyxelVpn300-
ZyxelVpn50 Firmware>= 4.35, <= 5.20
ZyxelVpn50-
ZyxelAtp100 Firmware>= 4.35, <= 5.20
ZyxelAtp100-
ZyxelAtp100W Firmware>= 4.35, <= 5.20
ZyxelAtp100W-
ZyxelAtp200 Firmware>= 4.35, <= 5.20
ZyxelAtp200-
ZyxelAtp500 Firmware>= 4.35, <= 5.20
ZyxelAtp500-
ZyxelAtp700 Firmware>= 4.35, <= 5.20
ZyxelAtp700-
ZyxelAtp800 Firmware>= 4.35, <= 5.20
ZyxelAtp800-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-0734?

CVE-2022-0734 is a vulnerability with a CVSS score of 5.8 (MEDIUM). A cross-site scripting vulnerability was identified in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.35 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series f...

How severe is CVE-2022-0734?

CVE-2022-0734 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-0734?

Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Vpn100 Firmware, Zyxel Vpn100, Zyxel Vpn1000 Firmware, Zyxel Vpn1000, Zyxel Vpn300 Firmware.