VulnerabilityModified
CVE-2018-9129
ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.
MEDIUM 5.9EPSS 0.97%
Does this matter?
Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.
Description
ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Affected
- zyxel/zywall 110 firmware · zyxel/zywall 1100 firmware · zyxel/zywall 310 firmware · zyxel/zywall vpn 50 firmware · zyxel/zywall vpn 100 firmware · zyxel/zywall vpn 300 firmware · zyxel/usg 20w firmware · zyxel/usg 40 firmware · zyxel/usg 40w firmware · zyxel/usg 60 firmware · zyxel/usg 60w firmware · zyxel/usg 110 firmware · zyxel/usg 2200-vpn firmware · zyxel/usg 310 firmware · zyxel/usg 1100 firmware · zyxel/usg 1900 firmware · zyxel/usg 20w-vpn firmware
- Source
- cve@mitre.org
References
- ftp://ftp.zyxel.com/USG110/firmware/USG110_4.32%28AAPH.0%29C0_2.pdf
- https://web-in-security.blogspot.com/2018/08/practical-bleichenbacher-attacks-on-ipsec-ike.htmlThird Party Advisory
- https://www.zyxel.com/support/bleichenbacher_attack_vulnerability.shtmlPatch, Vendor Advisory
- ftp://ftp.zyxel.com/USG110/firmware/USG110_4.32%28AAPH.0%29C0_2.pdf
- https://web-in-security.blogspot.com/2018/08/practical-bleichenbacher-attacks-on-ipsec-ike.htmlThird Party Advisory
- https://www.zyxel.com/support/bleichenbacher_attack_vulnerability.shtmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.