target entity

Multiple Firewalls

5 source-linked records in the current knowledge graph.

high

CVE-2024-11667: Zyxel Multiple Firewalls Path Traversal Vulnerability

Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-11667EPSS 3.0%Multiple FirewallsZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-33009: Zyxel Multiple Firewalls Buffer Overflow Vulnerability

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. Required action: Apply updates per vendor instructions.

CVE-2023-33009EPSS 28.1%Multiple FirewallsZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-33010: Zyxel Multiple Firewalls Buffer Overflow Vulnerability

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device. Required action: Apply updates per vendor instructions.

CVE-2023-33010EPSS 28.8%Multiple FirewallsZyxel
CISA KEV ↗ · unattributed attribution
high

CVE-2023-28771: Zyxel Multiple Firewalls OS Command Injection Vulnerability

Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device. Required action: Apply updates per vendor instructions.

CVE-2023-28771EPSS 99.3%Multiple FirewallsZyxel
CISA KEV ↗ · unattributed attribution