CVE-2023-28771
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Zyxel Multiple Firewalls OS Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 99% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-78
מוצרים מושפעים
zyxel: atp100 firmware; zyxel: atp100; zyxel: atp100w firmware; zyxel: atp100w; zyxel: atp200 firmware; zyxel: atp200; zyxel: atp500 firmware; zyxel: atp500; zyxel: atp700 firmware; zyxel: atp700; zyxel: atp800 firmware; zyxel: atp800; zyxel: usg flex 100 firmware; zyxel: usg flex 100; zyxel: usg flex 100w firmware
קישורים
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-adv… Vendor Advisory
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-adv… Vendor Advisory
- http://packetstormsecurity.com/files/172820/Zyxel-IKE-Packet-Decoder-Unauthent… ExploitThird Party Advisory
- http://packetstormsecurity.com/files/172820/Zyxel-IKE-Packet-Decoder-Unauthent… ExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource