← Back

CVE-2024-42057

nvd nist
Published: Sep 3, 2024Modified: Dec 13, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: security@zyxel.com.tw (Secondary)

Description

A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an unauthenticated attacker to execute some OS commands on an affected device by sending a crafted username to the vulnerable device. Note that this attack could be successful only if the device was configured in User-Based-PSK authentication mode and a valid user with a long username exceeding 28 characters exists.

Affected (3)

Products: Zyxel: Zld
1 product
Zld
Configuration A
1 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
From 4.32 to 5.39
Running on/withPlatform Versions
Zyxel
Atp100
All versions
Zyxel
Atp100w
All versions
Zyxel
Atp200
All versions
Zyxel
Atp500
All versions
Zyxel
Atp700
All versions
Zyxel
Atp800
All versions
Configuration B
1 vulnerable · 7 platform
Vulnerable SoftwareAffected Versions
From 4.50 to 5.39
Running on/withPlatform Versions
Zyxel
Usg Flex 100
All versions
Zyxel
Usg Flex 100ax
All versions
Zyxel
Usg Flex 100w
All versions
Zyxel
Usg Flex 200
All versions
Zyxel
Usg Flex 50
All versions
Zyxel
Usg Flex 500
All versions
Zyxel
Usg Flex 700
All versions
Configuration C
1 platform
Running on/withPlatform Versions
Zyxel
Usg Flex 50w
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 4.16 to 5.39
Running on/withPlatform Versions
Zyxel
Usg 20w Vpn
All versions

Timeline

No history available yet.