← Back

CVE-2023-4398

nvd nist
Published: Nov 28, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions on an affected device by sending a crafted IKE packet.

Affected (4)

Products: Zyxel: Zld
1 product
Zld
Configuration A
1 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
From 4.32 to 5.37
Running on/withPlatform Versions
Zyxel
Atp100
All versions
Zyxel
Atp100w
All versions
Zyxel
Atp200
All versions
Zyxel
Atp500
All versions
Zyxel
Atp700
All versions
Zyxel
Atp800
All versions
Configuration B
1 vulnerable · 7 platform
Vulnerable SoftwareAffected Versions
From 4.50 to 5.37
Running on/withPlatform Versions
Zyxel
Usg Flex 100
All versions
Zyxel
Usg Flex 100w
All versions
Zyxel
Usg Flex 200
All versions
Zyxel
Usg Flex 50
All versions
Zyxel
Usg Flex 500
All versions
Zyxel
Usg Flex 50w
All versions
Zyxel
Usg Flex 700
All versions
Configuration C
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
From 4.16 to 5.37
Running on/withPlatform Versions
Zyxel
Usg 20w Vpn
All versions
Zyxel
Vpn50w
All versions
Configuration D
1 vulnerable · 4 platform
Vulnerable SoftwareAffected Versions
From 4.30 to 5.37
Running on/withPlatform Versions
Zyxel
Vpn100
All versions
Zyxel
Vpn1000
All versions
Zyxel
Vpn300
All versions
Zyxel
Vpn50
All versions

Timeline

No history available yet.