PT-2023-3687 · Zyxel · Zyxel Atp Series+4

Atdog

·

Publicado

2023-03-23

·

Atualizado

2023-07-26

·

CVE-2023-28767

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zyxel ATP series versions 5.10 through 5.36 Zyxel USG FLEX series versions 5.00 through 5.36 Zyxel USG FLEX 50(W) series versions 5.10 through 5.36 Zyxel USG20(W)-VPN series versions 5.10 through 5.36 Zyxel VPN series versions 5.00 through 5.36
Description The configuration parser fails to sanitize user-controlled input in the affected Zyxel devices. An unauthenticated, LAN-based attacker could leverage this issue to inject operating system (OS) commands into the device configuration data on an affected device when the cloud management mode is enabled.
Recommendations For Zyxel ATP series versions 5.10 through 5.36, update to a version that includes a fix for this issue. For Zyxel USG FLEX series versions 5.00 through 5.36, update to a version that includes a fix for this issue. For Zyxel USG FLEX 50(W) series versions 5.10 through 5.36, update to a version that includes a fix for this issue. For Zyxel USG20(W)-VPN series versions 5.10 through 5.36, update to a version that includes a fix for this issue. For Zyxel VPN series versions 5.00 through 5.36, update to a version that includes a fix for this issue. As a temporary workaround, consider disabling the cloud management mode until a patch is available.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03972
CVE-2023-28767

Produtos afetados

Zyxel Atp Series
Zyxel Usg Flex 50(W) Series
Zyxel Usg Flex Series
Zyxel Usg20(W)-Vpn Series
Zyxel Vpn Series