CVE-2023-28771
Zyxel Multiple Firewalls OS Command Injection Vulnerability
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
-
*SSVC
Descriptions
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-03-23 CVE Reserved
- 2023-04-25 CVE Published
- 2023-05-23 First Exploit
- 2023-05-31 Exploited in Wild
- 2023-06-21 KEV Due Date
- 2024-08-02 CVE Updated
- 2024-11-15 EPSS Updated
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (4)
URL | Date | SRC |
---|---|---|
https://github.com/benjaminhays/CVE-2023-28771-PoC | 2023-05-23 | |
http://packetstormsecurity.com/files/172820/Zyxel-IKE-Packet-Decoder-Unauthenticated-Remote-Code-Execution.html | 2024-08-02 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zyxel Search vendor "Zyxel" | Atp100 Firmware Search vendor "Zyxel" for product "Atp100 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Atp100 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Atp100 Search vendor "Zyxel" for product "Atp100" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Atp100w Firmware Search vendor "Zyxel" for product "Atp100w Firmware" | >= 4.60 < 5.35 Search vendor "Zyxel" for product "Atp100w Firmware" and version " >= 4.60 < 5.35" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Atp100w Search vendor "Zyxel" for product "Atp100w" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Atp200 Firmware Search vendor "Zyxel" for product "Atp200 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Atp200 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Atp200 Search vendor "Zyxel" for product "Atp200" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Atp500 Firmware Search vendor "Zyxel" for product "Atp500 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Atp500 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Atp500 Search vendor "Zyxel" for product "Atp500" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Atp700 Firmware Search vendor "Zyxel" for product "Atp700 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Atp700 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Atp700 Search vendor "Zyxel" for product "Atp700" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Atp800 Firmware Search vendor "Zyxel" for product "Atp800 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Atp800 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Atp800 Search vendor "Zyxel" for product "Atp800" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 100 Firmware Search vendor "Zyxel" for product "Usg Flex 100 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Usg Flex 100 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 100 Search vendor "Zyxel" for product "Usg Flex 100" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 100w Firmware Search vendor "Zyxel" for product "Usg Flex 100w Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Usg Flex 100w Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 100w Search vendor "Zyxel" for product "Usg Flex 100w" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 200 Firmware Search vendor "Zyxel" for product "Usg Flex 200 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Usg Flex 200 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 200 Search vendor "Zyxel" for product "Usg Flex 200" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 50 Firmware Search vendor "Zyxel" for product "Usg Flex 50 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Usg Flex 50 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 50 Search vendor "Zyxel" for product "Usg Flex 50" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 500 Firmware Search vendor "Zyxel" for product "Usg Flex 500 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Usg Flex 500 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 500 Search vendor "Zyxel" for product "Usg Flex 500" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 50w Firmware Search vendor "Zyxel" for product "Usg Flex 50w Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Usg Flex 50w Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 50w Search vendor "Zyxel" for product "Usg Flex 50w" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 700 Firmware Search vendor "Zyxel" for product "Usg Flex 700 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Usg Flex 700 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 700 Search vendor "Zyxel" for product "Usg Flex 700" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Vpn100 Firmware Search vendor "Zyxel" for product "Vpn100 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Vpn100 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Vpn100 Search vendor "Zyxel" for product "Vpn100" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Vpn1000 Firmware Search vendor "Zyxel" for product "Vpn1000 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Vpn1000 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Vpn1000 Search vendor "Zyxel" for product "Vpn1000" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Vpn300 Firmware Search vendor "Zyxel" for product "Vpn300 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Vpn300 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Vpn300 Search vendor "Zyxel" for product "Vpn300" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Vpn50 Firmware Search vendor "Zyxel" for product "Vpn50 Firmware" | >= 4.60 < 5.36 Search vendor "Zyxel" for product "Vpn50 Firmware" and version " >= 4.60 < 5.36" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Vpn50 Search vendor "Zyxel" for product "Vpn50" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Usg 310 Firmware Search vendor "Zyxel" for product "Zywall Usg 310 Firmware" | >= 4.60 < 4.73 Search vendor "Zyxel" for product "Zywall Usg 310 Firmware" and version " >= 4.60 < 4.73" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Usg 310 Search vendor "Zyxel" for product "Zywall Usg 310" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Usg 310 Firmware Search vendor "Zyxel" for product "Zywall Usg 310 Firmware" | 4.73 Search vendor "Zyxel" for product "Zywall Usg 310 Firmware" and version "4.73" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Usg 310 Search vendor "Zyxel" for product "Zywall Usg 310" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Usg 100 Firmware Search vendor "Zyxel" for product "Zywall Usg 100 Firmware" | >= 4.60 < 4.73 Search vendor "Zyxel" for product "Zywall Usg 100 Firmware" and version " >= 4.60 < 4.73" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Usg 100 Search vendor "Zyxel" for product "Zywall Usg 100" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Usg 100 Firmware Search vendor "Zyxel" for product "Zywall Usg 100 Firmware" | 4.73 Search vendor "Zyxel" for product "Zywall Usg 100 Firmware" and version "4.73" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Usg 100 Search vendor "Zyxel" for product "Zywall Usg 100" | - | - |
Safe
|