TROYANOSYVIRUS
Voltar para CVEs

CVE-2023-28767

HIGH
8.8

Descricao

The configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX series firmware versions 5.00 through 5.36,  USG FLEX 50(W) series firmware versions 5.10 through 5.36, USG20(W)-VPN series firmware versions 5.10 through 5.36, and VPN series firmware versions 5.00 through 5.36. An unauthenticated, LAN-based attacker could leverage the vulnerability to inject some operating system (OS) commands into the device configuration data on an affected device when the cloud management mode is enabled.

Detalhes CVE

Pontuacao CVSS v3.18.8
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueADJACENT_NETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado7/17/2023
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0

Produtos afetados

zyxel:usg_20w-vpnzyxel:usg_20w-vpn_firmwarezyxel:usg_2200-vpnzyxel:usg_2200-vpn_firmwarezyxel:usg_flex_100zyxel:usg_flex_100_firmwarezyxel:usg_flex_100wzyxel:usg_flex_100w_firmwarezyxel:usg_flex_200zyxel:usg_flex_200_firmwarezyxel:usg_flex_50zyxel:usg_flex_500zyxel:usg_flex_500_firmwarezyxel:usg_flex_50_firmwarezyxel:usg_flex_50wzyxel:usg_flex_50w_firmwarezyxel:usg_flex_700zyxel:usg_flex_700_firmwarezyxel:zywall_atp100zyxel:zywall_atp100_firmwarezyxel:zywall_atp100wzyxel:zywall_atp100w_firmwarezyxel:zywall_atp200zyxel:zywall_atp200_firmwarezyxel:zywall_atp500zyxel:zywall_atp500_firmwarezyxel:zywall_atp700zyxel:zywall_atp700_firmwarezyxel:zywall_atp800zyxel:zywall_atp800_firmwarezyxel:zywall_vpn100zyxel:zywall_vpn100_firmwarezyxel:zywall_vpn2szyxel:zywall_vpn2s_firmwarezyxel:zywall_vpn300zyxel:zywall_vpn300_firmwarezyxel:zywall_vpn50zyxel:zywall_vpn50_firmwarezyxel:zywall_vpn_100zyxel:zywall_vpn_100_firmwarezyxel:zywall_vpn_300zyxel:zywall_vpn_300_firmwarezyxel:zywall_vpn_50zyxel:zywall_vpn_50_firmware

Fraquezas (CWE)

CWE-78CWE-78

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.