CVE-2023-33012
Zyxel parse_config.py Command Injection
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36 Patch 2, and VPN series firmware versions 5.00 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands by using a crafted GRE configuration when the cloud management mode is enabled.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-05-17 CVE Reserved
- 2023-07-17 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zyxel Search vendor "Zyxel" | Usg 20w-vpn Firmware Search vendor "Zyxel" for product "Usg 20w-vpn Firmware" | >= 5.10 < 5.37 Search vendor "Zyxel" for product "Usg 20w-vpn Firmware" and version " >= 5.10 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg 20w-vpn Search vendor "Zyxel" for product "Usg 20w-vpn" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg 2200-vpn Firmware Search vendor "Zyxel" for product "Usg 2200-vpn Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Usg 2200-vpn Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg 2200-vpn Search vendor "Zyxel" for product "Usg 2200-vpn" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 100 Firmware Search vendor "Zyxel" for product "Usg Flex 100 Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Usg Flex 100 Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 100 Search vendor "Zyxel" for product "Usg Flex 100" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 100w Firmware Search vendor "Zyxel" for product "Usg Flex 100w Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Usg Flex 100w Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 100w Search vendor "Zyxel" for product "Usg Flex 100w" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 200 Firmware Search vendor "Zyxel" for product "Usg Flex 200 Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Usg Flex 200 Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 200 Search vendor "Zyxel" for product "Usg Flex 200" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 50 Firmware Search vendor "Zyxel" for product "Usg Flex 50 Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Usg Flex 50 Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 50 Search vendor "Zyxel" for product "Usg Flex 50" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 500 Firmware Search vendor "Zyxel" for product "Usg Flex 500 Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Usg Flex 500 Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 500 Search vendor "Zyxel" for product "Usg Flex 500" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 50w Firmware Search vendor "Zyxel" for product "Usg Flex 50w Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Usg Flex 50w Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 50w Search vendor "Zyxel" for product "Usg Flex 50w" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Usg Flex 700 Firmware Search vendor "Zyxel" for product "Usg Flex 700 Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Usg Flex 700 Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Usg Flex 700 Search vendor "Zyxel" for product "Usg Flex 700" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Atp100 Firmware Search vendor "Zyxel" for product "Zywall Atp100 Firmware" | >= 5.10 < 5.37 Search vendor "Zyxel" for product "Zywall Atp100 Firmware" and version " >= 5.10 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Atp100 Search vendor "Zyxel" for product "Zywall Atp100" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Atp100w Firmware Search vendor "Zyxel" for product "Zywall Atp100w Firmware" | >= 5.10 < 5.37 Search vendor "Zyxel" for product "Zywall Atp100w Firmware" and version " >= 5.10 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Atp100w Search vendor "Zyxel" for product "Zywall Atp100w" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Atp200 Firmware Search vendor "Zyxel" for product "Zywall Atp200 Firmware" | >= 5.10 < 5.37 Search vendor "Zyxel" for product "Zywall Atp200 Firmware" and version " >= 5.10 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Atp200 Search vendor "Zyxel" for product "Zywall Atp200" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Atp500 Firmware Search vendor "Zyxel" for product "Zywall Atp500 Firmware" | >= 5.10 < 5.37 Search vendor "Zyxel" for product "Zywall Atp500 Firmware" and version " >= 5.10 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Atp500 Search vendor "Zyxel" for product "Zywall Atp500" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Atp700 Firmware Search vendor "Zyxel" for product "Zywall Atp700 Firmware" | >= 5.10 < 5.37 Search vendor "Zyxel" for product "Zywall Atp700 Firmware" and version " >= 5.10 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Atp700 Search vendor "Zyxel" for product "Zywall Atp700" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Atp800 Firmware Search vendor "Zyxel" for product "Zywall Atp800 Firmware" | >= 5.10 < 5.37 Search vendor "Zyxel" for product "Zywall Atp800 Firmware" and version " >= 5.10 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Atp800 Search vendor "Zyxel" for product "Zywall Atp800" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Vpn100 Firmware Search vendor "Zyxel" for product "Zywall Vpn100 Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Zywall Vpn100 Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Vpn100 Search vendor "Zyxel" for product "Zywall Vpn100" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Vpn2s Firmware Search vendor "Zyxel" for product "Zywall Vpn2s Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Zywall Vpn2s Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Vpn2s Search vendor "Zyxel" for product "Zywall Vpn2s" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Vpn300 Firmware Search vendor "Zyxel" for product "Zywall Vpn300 Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Zywall Vpn300 Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Vpn300 Search vendor "Zyxel" for product "Zywall Vpn300" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Vpn50 Firmware Search vendor "Zyxel" for product "Zywall Vpn50 Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Zywall Vpn50 Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Vpn50 Search vendor "Zyxel" for product "Zywall Vpn50" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Vpn 100 Firmware Search vendor "Zyxel" for product "Zywall Vpn 100 Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Zywall Vpn 100 Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Vpn 100 Search vendor "Zyxel" for product "Zywall Vpn 100" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Vpn 300 Firmware Search vendor "Zyxel" for product "Zywall Vpn 300 Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Zywall Vpn 300 Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Vpn 300 Search vendor "Zyxel" for product "Zywall Vpn 300" | - | - |
Safe
|
Zyxel Search vendor "Zyxel" | Zywall Vpn 50 Firmware Search vendor "Zyxel" for product "Zywall Vpn 50 Firmware" | >= 5.00 < 5.37 Search vendor "Zyxel" for product "Zywall Vpn 50 Firmware" and version " >= 5.00 < 5.37" | - |
Affected
| in | Zyxel Search vendor "Zyxel" | Zywall Vpn 50 Search vendor "Zyxel" for product "Zywall Vpn 50" | - | - |
Safe
|