PT-2023-22605 · Zyxel · Usg20(W)-Vpn Series+3

Fabiano Golluscio

·

Publicado

2023-05-29

·

Atualizado

2026-05-15

·

CVE-2023-30253

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dolibarr versions prior to 17.0.1 Zyxel ATP Series, USG FLEX Series, USG FLEX 50(W) Series, and USG20(W)-VPN Series (affected versions not specified)
Description The issue allows remote code execution by an authenticated user via an uppercase manipulation in injected data, such as using <?PHP instead of <?php. This can be exploited in certain Zyxel products, including the ATP Series, USG FLEX Series, USG FLEX 50(W) Series, and USG20(W)-VPN Series, although specific details about the exploitation in these products are not provided.
Recommendations For Dolibarr versions prior to 17.0.1, update to version 17.0.1 or later to resolve the issue. For Zyxel ATP Series, USG FLEX Series, USG FLEX 50(W) Series, and USG20(W)-VPN Series, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-DOLIBARR-2023-30253
CVE-2023-30253
GHSA-9WQR-5JP4-MJMH

Produtos afetados

Usg Flex 50(W) Series
Usg Flex H Series
Usg20(W)-Vpn Series
Zyxel Atp Series