PT-2023-3687 · Zyxel · Zyxel Atp Series+4
Atdog
·
Publicado
2023-03-23
·
Atualizado
2023-07-26
·
CVE-2023-28767
CVSS v3.1
8.8
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zyxel ATP series versions 5.10 through 5.36
Zyxel USG FLEX series versions 5.00 through 5.36
Zyxel USG FLEX 50(W) series versions 5.10 through 5.36
Zyxel USG20(W)-VPN series versions 5.10 through 5.36
Zyxel VPN series versions 5.00 through 5.36
Description
The configuration parser fails to sanitize user-controlled input in the affected Zyxel devices. An unauthenticated, LAN-based attacker could leverage this issue to inject operating system (OS) commands into the device configuration data on an affected device when the cloud management mode is enabled.
Recommendations
For Zyxel ATP series versions 5.10 through 5.36, update to a version that includes a fix for this issue.
For Zyxel USG FLEX series versions 5.00 through 5.36, update to a version that includes a fix for this issue.
For Zyxel USG FLEX 50(W) series versions 5.10 through 5.36, update to a version that includes a fix for this issue.
For Zyxel USG20(W)-VPN series versions 5.10 through 5.36, update to a version that includes a fix for this issue.
For Zyxel VPN series versions 5.00 through 5.36, update to a version that includes a fix for this issue.
As a temporary workaround, consider disabling the cloud management mode until a patch is available.
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zyxel Atp Series
Zyxel Usg Flex 50(W) Series
Zyxel Usg Flex Series
Zyxel Usg20(W)-Vpn Series
Zyxel Vpn Series