CVE-2023-28767

CVSS V2 None CVSS V3 None
Description
The configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX series firmware versions 5.00 through 5.36,  USG FLEX 50(W) series firmware versions 5.10 through 5.36, USG20(W)-VPN series firmware versions 5.10 through 5.36, and VPN series firmware versions 5.00 through 5.36. An unauthenticated, LAN-based attacker could leverage the vulnerability to inject some operating system (OS) commands into the device configuration data on an affected device when the cloud management mode is enabled.
Overview
  • CVE ID
  • CVE-2023-28767
  • Assigner
  • Zyxel
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-07-17T16:59:45.258Z
  • Last Modified Date
  • 2023-07-17T16:59:45.258Z
History
Created Old Value New Value Data Type Notes
2024-06-25 10:48:57 Added to TrackCVE