cbcvebase.
CVE-2023-22916
published 2023-04-24

CVE-2023-22916: The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware…

high8.1CVSS 3.1
AVNACLPRNUIRSUCNIHAH
The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware versions 5.10 through 5.35, USG20(W)-VPN firmware versions 5.10 through 5.35, and VPN series firmware versions 5.00 through 5.35, which fails to properly sanitize user input. A remote unauthenticated attacker could leverage the vulnerability to modify device configuration data, resulting in DoS conditions on an affected device if the attacker could trick an authorized administrator to switch the management mode to the cloud mode.

Affected

23 ranges
VendorProductVersion rangeFixed in
zyxelatp100_firmware5.10 – 5.35
zyxelatp100w_firmware5.10 – 5.35
zyxelatp200_firmware5.10 – 5.35
zyxelatp500_firmware5.10 – 5.35
zyxelatp700_firmware5.10 – 5.35
zyxelatp800_firmware5.10 – 5.35
zyxelatp_series_firmware
zyxelusg20_vpn_firmware
zyxelusg_20w-vpn_firmware5.10 – 5.35
zyxelusg_flex_100_firmware5.00 – 5.35
zyxelusg_flex_100w_firmware5.00 – 5.35
zyxelusg_flex_200_firmware5.00 – 5.35
zyxelusg_flex_500_firmware5.00 – 5.35
zyxelusg_flex_50_firmware
zyxelusg_flex_50_firmware5.00 – 5.35
zyxelusg_flex_50w_firmware5.10 – 5.35
zyxelusg_flex_700_firmware5.00 – 5.35
zyxelusg_flex_series_firmware
zyxelvpn1000_firmware5.00 – 5.35
zyxelvpn100_firmware5.00 – 5.35
zyxelvpn300_firmware5.00 – 5.35
zyxelvpn50_firmware5.00 – 5.35
zyxelvpn_series_firmware