8.1

CVE-2024-42057

A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an unauthenticated attacker to execute some OS commands on an affected device by sending a crafted username to the vulnerable device. Note that this attack could be successful only if the device was configured in User-Based-PSK authentication mode and a valid user with a long username exceeding 28 characters exists.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zyxel ≫ Zld Version >= 4.32 < 5.39
   Zyxel ≫ Atp100 Version -
   Zyxel ≫ Atp100w Version -
   Zyxel ≫ Atp200 Version -
   Zyxel ≫ Atp500 Version -
   Zyxel ≫ Atp700 Version -
   Zyxel ≫ Atp800 Version -
Zyxel ≫ Zld Version >= 4.50 < 5.39
   Zyxel ≫ Usg Flex 100 Version -
   Zyxel ≫ Usg Flex 100ax Version -
   Zyxel ≫ Usg Flex 100w Version -
   Zyxel ≫ Usg Flex 200 Version -
   Zyxel ≫ Usg Flex 50 Version -
   Zyxel ≫ Usg Flex 500 Version -
   Zyxel ≫ Usg Flex 700 Version -
Zyxel ≫ Zld Version >= 4.16 < 5.39
   Zyxel ≫ Usg Flex 50w Version -
Zyxel ≫ Zld Version >= 4.16 < 5.39
   Zyxel ≫ Usg 20w-vpn Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.32% 0.671
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@zyxel.com.tw 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-firewalls-09-03-2024
Vendor Advisory