Vulnerability Description
ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Zywall 110 Firmware | - |
| Zyxel | Zywall 110 | - |
| Zyxel | Zywall 1100 Firmware | - |
| Zyxel | Zywall 1100 | - |
| Zyxel | Zywall 310 Firmware | - |
| Zyxel | Zywall 310 | - |
| Zyxel | Zywall Vpn 50 Firmware | - |
| Zyxel | Zywall Vpn 50 | - |
| Zyxel | Zywall Vpn 100 Firmware | - |
| Zyxel | Zywall Vpn 100 | - |
| Zyxel | Zywall Vpn 300 Firmware | - |
| Zyxel | Zywall Vpn 300 | - |
| Zyxel | Usg 20W Firmware | - |
| Zyxel | Usg 20W | - |
| Zyxel | Usg 40 Firmware | - |
| Zyxel | Usg 40 | - |
| Zyxel | Usg 40W Firmware | - |
| Zyxel | Usg 40W | - |
| Zyxel | Usg 60 Firmware | - |
| Zyxel | Usg 60 | - |
References
- ftp://ftp.zyxel.com/USG110/firmware/USG110_4.32%28AAPH.0%29C0_2.pdf
- https://web-in-security.blogspot.com/2018/08/practical-bleichenbacher-attacks-onThird Party Advisory
- https://www.zyxel.com/support/bleichenbacher_attack_vulnerability.shtmlPatchVendor Advisory
- ftp://ftp.zyxel.com/USG110/firmware/USG110_4.32%28AAPH.0%29C0_2.pdf
- https://web-in-security.blogspot.com/2018/08/practical-bleichenbacher-attacks-onThird Party Advisory
- https://www.zyxel.com/support/bleichenbacher_attack_vulnerability.shtmlPatchVendor Advisory
FAQ
What is CVE-2018-9129?
CVE-2018-9129 is a vulnerability with a CVSS score of 5.9 (MEDIUM). ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.
How severe is CVE-2018-9129?
CVE-2018-9129 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-9129?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Zywall 110 Firmware, Zyxel Zywall 110, Zyxel Zywall 1100 Firmware, Zyxel Zywall 1100, Zyxel Zywall 310 Firmware.