CVE-2023-28771
Zyxel Multiple Firewalls OS Command Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 21 June 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.28% probability · 100th percentile
- CISA KEV
- Listed 31 May 2023 · due 21 June 2023
- Weakness
- CWE-78
- Affected
- zyxel/atp100 firmware · zyxel/atp100w firmware · zyxel/atp200 firmware · zyxel/atp500 firmware · zyxel/atp700 firmware · zyxel/atp800 firmware · zyxel/usg flex 100 firmware · zyxel/usg flex 100w firmware · zyxel/usg flex 200 firmware · zyxel/usg flex 50 firmware · zyxel/usg flex 500 firmware · zyxel/usg flex 50w firmware · zyxel/usg flex 700 firmware · zyxel/vpn100 firmware · zyxel/vpn1000 firmware · zyxel/vpn300 firmware · zyxel/vpn50 firmware · zyxel/zywall usg 310 firmware · zyxel/zywall usg 100 firmware
- Source
- security@zyxel.com.tw
CISA notes
Apply updates per vendor instructions. https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls; https://nvd.nist.gov/vuln/detail/CVE-2023-28771
References
- http://packetstormsecurity.com/files/172820/Zyxel-IKE-Packet-Decoder-Unauthenticated-Remote-Code-Execution.htmlExploit, Third Party Advisory
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewallsVendor Advisory
- http://packetstormsecurity.com/files/172820/Zyxel-IKE-Packet-Decoder-Unauthenticated-Remote-Code-Execution.htmlExploit, Third Party Advisory
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewallsVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28771US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.