Umbra Wiki cve cve/CVE-2023-28771
Back to wiki

CVE-2023-28771 — Zyxel Multiple Firewalls OS Command Injection Vulnerability

provenance: imported · CVE: CVE-2023-28771 · CWE: CWE-78

CVE-2023-28771: Zyxel Multiple Firewalls OS Command Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Zyxel
Product Multiple Firewalls
Date added 2023-05-31
Due date 2023-06-21
Ransomware campaign use Unknown

Description

Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls; https://nvd.nist.gov/vuln/detail/CVE-2023-28771

Weakness behind it

CISA records this vulnerability as an instance of CWE-78. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2023-28771
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →