cbcvebase.

Zyxel Usg20 Vpn Firmware vulnerabilities

8 known vulnerabilities affecting zyxel/usg20_vpn_firmware.

Total CVEs
8
CISA KEV
2
actively exploited
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH4MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2023-33010P1CRITICALCVSS 9.8KEVv4.25 through 5.36 Patch 12023-05-24
CVE-2023-33010 [CRITICAL] CWE-120 CVE-2023-33010: A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.
nvd
CVE-2023-33009P1CRITICALCVSS 9.8KEVv4.60 through 5.36 Patch 12023-05-24
CVE-2023-33009 [CRITICAL] CWE-120 CVE-2023-33009: A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4 A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.
nvd
CVE-2023-27991P2HIGHCVSS 8.8v4.16 through 5.352023-04-24
CVE-2023-27991 [HIGH] CWE-78 CVE-2023-27991: The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmw The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could all
nvd
CVE-2023-22915P3HIGHCVSS 7.5v4.30 through 5.352023-04-24
CVE-2023-22915 [HIGH] CWE-120 CVE-2023-22915: A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series fir A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.30 through 5.35, USG20(W)-VPN firmware versions 4.30 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote unauthenticated attacker to cause DoS
nvd
CVE-2023-22916P3HIGHCVSS 8.1v5.10 through 5.352023-04-24
CVE-2023-22916 [HIGH] CWE-20 CVE-2023-22916: The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series fi The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware versions 5.10 through 5.35, USG20(W)-VPN firmware versions 5.10 through 5.35, and VPN series firmware versions 5.00 through 5.35, which fails to properly sanitize user input. A remote unauthentic
nvd
CVE-2023-22917P3HIGHCVSS 7.5v5.10 through 5.322023-04-24
CVE-2023-22917 [HIGH] CWE-120 CVE-2023-22917: A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware version A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32, and VPN series firmware versions 5.00 through 5.35, which could allow a remot
nvd
CVE-2023-22918P3MEDIUMCVSS 6.5v4.16 through 5.352023-04-24
CVE-2023-22918 [MEDIUM] CWE-359 CVE-2023-22918: A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firm A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmwa
nvd
CVE-2023-27990P4MEDIUMCVSS 4.8v4.16 through 5.352023-04-24
CVE-2023-27990 [MEDIUM] CWE-79 CVE-2023-27990: The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35 The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker
nvd
Zyxel Usg20 Vpn Firmware vulnerabilities | cvebase