cbcvebase.

Zyxel Usg20 Vpn Series Firmware vulnerabilities

27 known vulnerabilities affecting zyxel/usg20_vpn_series_firmware.

Total CVEs
27
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH15MEDIUM11

Vulnerabilities

Page 2 of 2
CVE-2023-35136P4MEDIUMCVSS 5.5vversions 4.16 through 5.372023-11-28
CVE-2023-35136 [MEDIUM] CWE-20 CVE-2023-35136: An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware An improper input validation vulnerability in the “Quagga” package of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, coul
nvd
CVE-2023-37925P4MEDIUMCVSS 5.5vversions 4.16 through 5.372023-11-28
CVE-2023-37925 [MEDIUM] CWE-269 CVE-2023-37925: An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firm An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, N
nvd
CVE-2023-5797P4MEDIUMCVSS 5.5vversions 4.16 through 5.372023-11-28
CVE-2023-5797 [MEDIUM] CWE-269 CVE-2023-5797: An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firm An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, NWA
nvd
CVE-2024-6343P4MEDIUMCVSS 4.9vversions V4.16 through V5.382024-09-03
CVE-2024-6343 [MEDIUM] CWE-120 CVE-2024-6343: A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an authenticated attacker with adm
nvd
CVE-2023-5650P4MEDIUMCVSS 5.5vversions 4.16 through 5.372023-11-28
CVE-2023-5650 [MEDIUM] CWE-269 CVE-2023-5650: An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow
nvd
CVE-2023-37926P4MEDIUMCVSS 5.5vversions 4.16 through 5.372023-11-28
CVE-2023-37926 [MEDIUM] CWE-120 CVE-2023-37926: A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLE A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow an authenticated local at
nvd
CVE-2023-4397P4MEDIUMCVSS 4.4v5.372023-11-28
CVE-2023-4397 [MEDIUM] CWE-120 CVE-2023-4397: A buffer overflow vulnerability in the Zyxel ATP series firmware version 5.37, USG FLEX series firmw A buffer overflow vulnerability in the Zyxel ATP series firmware version 5.37, USG FLEX series firmware version 5.37, USG FLEX 50(W) series firmware version 5.37, and USG20(W)-VPN series firmware version 5.37, could allow an authenticated local attacker with administrator privileges to cause denial-of-service (DoS) conditions by executing the CLI comm
nvd