peter bassill · operator
$ cve CVE-2023-28771 JSON

CVE-2023-28771 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 99.3% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2023-06-21.

Description

Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.28% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2023-06-21
Public exploitnone known
Published2023-04-25
Last modified2026-06-17

CISA KEV

NameZyxel Multiple Firewalls OS Command Injection Vulnerability
Added2023-05-31
Due2023-06-21
Vendor / productZyxel / Multiple Firewalls
Ransomware usenone reported

Affected (38)

VendorProduct
zyxelatp100
zyxelatp100 firmware
zyxelatp100w
zyxelatp100w firmware
zyxelatp200
zyxelatp200 firmware
zyxelatp500
zyxelatp500 firmware
zyxelatp700
zyxelatp700 firmware
zyxelatp800
zyxelatp800 firmware
zyxelusg flex 100
zyxelusg flex 100 firmware
zyxelusg flex 100w
zyxelusg flex 100w firmware
zyxelusg flex 200
zyxelusg flex 200 firmware
zyxelusg flex 50
zyxelusg flex 50 firmware
zyxelusg flex 500
zyxelusg flex 500 firmware
zyxelusg flex 50w
zyxelusg flex 50w firmware
zyxelusg flex 700
zyxelusg flex 700 firmware
zyxelvpn100
zyxelvpn100 firmware
zyxelvpn1000
zyxelvpn1000 firmware
zyxelvpn300
zyxelvpn300 firmware
zyxelvpn50
zyxelvpn50 firmware
zyxelzywall usg 100
zyxelzywall usg 100 firmware
zyxelzywall usg 310
zyxelzywall usg 310 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD