Technical Severity
CRITICALCVSS v3.1 Metrics
9.8
/ 10
Minimal Risk
Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitation Likelihood
EPSS Prediction
94.35
%
Predictive Probability
Percentile Rank
100.0
th
Documented as more likely to be exploited than 100.0% of known CVEs.
Detection Date
May 31, 2023
Remediation Due
Jun 21, 2023
CISA Catalog Active
Threat Analysis
Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.
Remediation Directive
Apply updates per vendor instructions.
External Intelligence
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls
NVD
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2023-28771