Vulnerability Description
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Atp100 Firmware | >= 4.60, < 5.36 |
| Zyxel | Atp100 | - |
| Zyxel | Atp100W Firmware | >= 4.60, < 5.35 |
| Zyxel | Atp100W | - |
| Zyxel | Atp200 Firmware | >= 4.60, < 5.36 |
| Zyxel | Atp200 | - |
| Zyxel | Atp500 Firmware | >= 4.60, < 5.36 |
| Zyxel | Atp500 | - |
| Zyxel | Atp700 Firmware | >= 4.60, < 5.36 |
| Zyxel | Atp700 | - |
| Zyxel | Atp800 Firmware | >= 4.60, < 5.36 |
| Zyxel | Atp800 | - |
| Zyxel | Usg Flex 100 Firmware | >= 4.60, < 5.36 |
| Zyxel | Usg Flex 100 | - |
| Zyxel | Usg Flex 100W Firmware | >= 4.60, < 5.36 |
| Zyxel | Usg Flex 100W | - |
| Zyxel | Usg Flex 200 Firmware | >= 4.60, < 5.36 |
| Zyxel | Usg Flex 200 | - |
| Zyxel | Usg Flex 50 Firmware | >= 4.60, < 5.36 |
| Zyxel | Usg Flex 50 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/172820/Zyxel-IKE-Packet-Decoder-UnauthenticExploitThird Party Advisory
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisVendor Advisory
- http://packetstormsecurity.com/files/172820/Zyxel-IKE-Packet-Decoder-UnauthenticExploitThird Party Advisory
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-US Government Resource
FAQ
What is CVE-2023-28771?
CVE-2023-28771 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and...
How severe is CVE-2023-28771?
CVE-2023-28771 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-28771?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Atp100 Firmware, Zyxel Atp100, Zyxel Atp100W Firmware, Zyxel Atp100W, Zyxel Atp200 Firmware.