A format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through 5.36 Patch 2, and VPN series firmware versions 5.00 through 5.36 Patch 2, could allow an unauthenticated, LAN-based attacker to execute some OS commands by using a crafted PPPoE configuration on an affected device when the cloud management mode is enabled.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
Configuration 16 (hide)
AND |
|
Configuration 17 (hide)
AND |
|
Configuration 18 (hide)
AND |
|
Configuration 19 (hide)
AND |
|
Configuration 20 (hide)
AND |
|
Configuration 21 (hide)
AND |
|
Configuration 22 (hide)
AND |
|
History
26 Jul 2023, 21:35
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-firewalls-and-wlan-controllers - Vendor Advisory | |
First Time |
Zyxel usg Flex 100 Firmware
Zyxel zywall Vpn50 Zyxel zywall Vpn100 Zyxel zywall Atp800 Firmware Zyxel zywall Atp100w Firmware Zyxel zywall Atp200 Firmware Zyxel zywall Vpn300 Zyxel usg Flex 500 Firmware Zyxel zywall Atp500 Zyxel usg Flex 50w Firmware Zyxel usg Flex 700 Zyxel usg 2200-vpn Zyxel zywall Vpn300 Firmware Zyxel zywall Vpn 300 Firmware Zyxel zywall Vpn 300 Zyxel zywall Vpn 50 Zyxel zywall Atp700 Zyxel usg Flex 200 Firmware Zyxel zywall Vpn 50 Firmware Zyxel usg Flex 50w Zyxel zywall Atp700 Firmware Zyxel usg 20w-vpn Zyxel zywall Atp500 Firmware Zyxel usg Flex 200 Zyxel Zyxel zywall Atp100w Zyxel zywall Vpn2s Firmware Zyxel zywall Atp200 Zyxel zywall Vpn 100 Zyxel zywall Vpn2s Zyxel zywall Vpn100 Firmware Zyxel usg 20w-vpn Firmware Zyxel usg Flex 100 Zyxel zywall Vpn50 Firmware Zyxel zywall Atp100 Firmware Zyxel usg Flex 100w Zyxel usg Flex 100w Firmware Zyxel usg Flex 50 Zyxel usg Flex 50 Firmware Zyxel zywall Atp100 Zyxel zywall Atp800 Zyxel usg Flex 700 Firmware Zyxel zywall Vpn 100 Firmware Zyxel usg 2200-vpn Firmware Zyxel usg Flex 500 |
|
CWE | CWE-134 | |
CPE | cpe:2.3:h:zyxel:usg_2200-vpn:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_100w:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_flex_100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_flex_500_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_700:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zywall_vpn_50_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:zywall_vpn_100:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:zywall_atp800:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_flex_100w_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zywall_vpn2s_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:zywall_atp700:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_100:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zywall_vpn_300_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:zywall_atp100:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zywall_atp700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_flex_50w_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_20w-vpn:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zywall_atp500_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:zywall_vpn100:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zywall_atp100_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:zywall_atp100w:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_200:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zywall_vpn_100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zywall_atp200_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:zywall_vpn2s:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_50w:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zywall_atp800_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_500:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zywall_atp100w_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:zywall_vpn_50:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:zywall_vpn50:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zywall_vpn100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zywall_vpn300_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_flex_700_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:zywall_vpn300:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:zywall_vpn_300:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_flex_50_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:usg_flex_50:-:*:*:*:*:*:*:* cpe:2.3:h:zyxel:zywall_atp500:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_20w-vpn_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_2200-vpn_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:zyxel:zywall_atp200:-:*:*:*:*:*:*:* cpe:2.3:o:zyxel:usg_flex_200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:zyxel:zywall_vpn50_firmware:*:*:*:*:*:*:*:* |
17 Jul 2023, 18:58
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-17 18:15
Updated : 2023-07-26 21:35
NVD link : CVE-2023-33011
Mitre link : CVE-2023-33011
JSON object : View
Products Affected
zyxel
- usg_flex_500
- zywall_vpn_300
- zywall_atp100
- zywall_vpn100_firmware
- zywall_atp500_firmware
- usg_flex_200_firmware
- zywall_atp200
- usg_flex_50
- usg_2200-vpn
- usg_flex_500_firmware
- zywall_atp700
- zywall_vpn2s_firmware
- zywall_atp100w
- zywall_vpn50_firmware
- zywall_vpn2s
- zywall_vpn_50_firmware
- usg_20w-vpn_firmware
- usg_flex_50w_firmware
- usg_2200-vpn_firmware
- zywall_atp800_firmware
- zywall_vpn50
- usg_flex_700_firmware
- zywall_atp700_firmware
- zywall_vpn_300_firmware
- zywall_atp800
- zywall_vpn300_firmware
- usg_flex_50w
- usg_flex_100w_firmware
- usg_flex_100
- usg_flex_100_firmware
- zywall_vpn300
- usg_flex_700
- zywall_vpn100
- zywall_vpn_100
- usg_20w-vpn
- zywall_atp200_firmware
- usg_flex_50_firmware
- zywall_atp500
- usg_flex_200
- zywall_atp100_firmware
- usg_flex_100w
- zywall_atp100w_firmware
- zywall_vpn_100_firmware
- zywall_vpn_50
CWE
CWE-134
Use of Externally-Controlled Format String