PT-2023-8181 · Zyxel · Zyxel Atp Series+4

CVE-2023-22916

·

Publicado

2023-04-24

·

Atualizado

2023-05-04

CVSS v2.0

9.4

Alta

VetorAV:N/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zyxel ATP series versions 5.10 through 5.35 Zyxel USG FLEX series versions 5.00 through 5.35 Zyxel USG FLEX 50(W) versions 5.10 through 5.35 Zyxel USG20(W)-VPN versions 5.10 through 5.35 Zyxel VPN series versions 5.00 through 5.35
Description The issue is related to insufficient input validation in the configuration parser of the affected Zyxel devices. This could allow a remote unauthenticated attacker to modify device configuration data, potentially leading to denial of service conditions if an authorized administrator is tricked into switching the management mode to cloud mode.
Recommendations For Zyxel ATP series versions 5.10 through 5.35, update to a version outside of this range to resolve the issue. For Zyxel USG FLEX series versions 5.00 through 5.35, update to a version outside of this range to resolve the issue. For Zyxel USG FLEX 50(W) versions 5.10 through 5.35, update to a version outside of this range to resolve the issue. For Zyxel USG20(W)-VPN versions 5.10 through 5.35, update to a version outside of this range to resolve the issue. For Zyxel VPN series versions 5.00 through 5.35, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the configuration parser to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-00169
CVE-2023-22916

Produtos afetados

Zyxel Atp Series
Zyxel Usg Flex 50
Zyxel Usg Flex Series
Zyxel Usg20(W)-Vpn
Zyxel Vpn Series