CVE-2023-22916
Summary
| CVE | CVE-2023-22916 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-24 17:15:00 UTC |
| Updated | 2023-05-04 19:35:00 UTC |
| Description | The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware versions 5.10 through 5.35, USG20(W)-VPN firmware versions 5.10 through 5.35, and VPN series firmware versions 5.00 through 5.35, which fails to properly sanitize user input. A remote unauthenticated attacker could leverage the vulnerability to modify device configuration data, resulting in DoS conditions on an affected device if the attacker could trick an authorized administrator to switch the management mode to the cloud mode. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Zyxel | Atp100 | - | All | All | All |
| Hardware | Zyxel | Atp100w | - | All | All | All |
| Operating System | Zyxel | Atp100w Firmware | All | All | All | All |
| Operating System | Zyxel | Atp100 Firmware | All | All | All | All |
| Hardware | Zyxel | Atp200 | - | All | All | All |
| Operating System | Zyxel | Atp200 Firmware | All | All | All | All |
| Hardware | Zyxel | Atp500 | - | All | All | All |
| Operating System | Zyxel | Atp500 Firmware | All | All | All | All |
| Hardware | Zyxel | Atp700 | - | All | All | All |
| Operating System | Zyxel | Atp700 Firmware | All | All | All | All |
| Hardware | Zyxel | Atp800 | - | All | All | All |
| Operating System | Zyxel | Atp800 Firmware | All | All | All | All |
| Hardware | Zyxel | Usg 20w-vpn | - | All | All | All |
| Operating System | Zyxel | Usg 20w-vpn Firmware | All | All | All | All |
| Hardware | Zyxel | Usg Flex 100 | - | All | All | All |
| Hardware | Zyxel | Usg Flex 100w | - | All | All | All |
| Operating System | Zyxel | Usg Flex 100w Firmware | All | All | All | All |
| Operating System | Zyxel | Usg Flex 100 Firmware | All | All | All | All |
| Hardware | Zyxel | Usg Flex 200 | - | All | All | All |
| Operating System | Zyxel | Usg Flex 200 Firmware | All | All | All | All |
| Hardware | Zyxel | Usg Flex 50 | - | All | All | All |
| Hardware | Zyxel | Usg Flex 500 | - | All | All | All |
| Operating System | Zyxel | Usg Flex 500 Firmware | All | All | All | All |
| Hardware | Zyxel | Usg Flex 50w | - | All | All | All |
| Operating System | Zyxel | Usg Flex 50w Firmware | All | All | All | All |
| Operating System | Zyxel | Usg Flex 50 Firmware | All | All | All | All |
| Hardware | Zyxel | Usg Flex 700 | - | All | All | All |
| Operating System | Zyxel | Usg Flex 700 Firmware | All | All | All | All |
| Hardware | Zyxel | Vpn100 | - | All | All | All |
| Hardware | Zyxel | Vpn1000 | - | All | All | All |
| Operating System | Zyxel | Vpn1000 Firmware | All | All | All | All |
| Operating System | Zyxel | Vpn100 Firmware | All | All | All | All |
| Hardware | Zyxel | Vpn300 | - | All | All | All |
| Operating System | Zyxel | Vpn300 Firmware | All | All | All | All |
| Hardware | Zyxel | Vpn50 | - | All | All | All |
| Operating System | Zyxel | Vpn50 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Page Not Found | Zyxel Networks | CONFIRM | www.zyxel.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.