HIGH · 7.5

CVE-2023-4398

An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware version...

Vulnerability Description

An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions on an affected device by sending a crafted IKE packet.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ZyxelZld>= 4.32, <= 5.37
ZyxelAtp100-
ZyxelAtp100W-
ZyxelAtp200-
ZyxelAtp500-
ZyxelAtp700-
ZyxelAtp800-
ZyxelUsg Flex 100-
ZyxelUsg Flex 100W-
ZyxelUsg Flex 200-
ZyxelUsg Flex 50-
ZyxelUsg Flex 500-
ZyxelUsg Flex 50W-
ZyxelUsg Flex 700-
ZyxelUsg 20W-Vpn-
ZyxelVpn50W-
ZyxelVpn100-
ZyxelVpn1000-
ZyxelVpn300-
ZyxelVpn50-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-4398?

CVE-2023-4398 is a vulnerability with a CVSS score of 7.5 (HIGH). An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware version...

How severe is CVE-2023-4398?

CVE-2023-4398 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-4398?

Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Zld, Zyxel Atp100, Zyxel Atp100W, Zyxel Atp200, Zyxel Atp500.