CVE-2018-9129

UnknownEPSS 0.97%

Last modified

CVE-2018-9129 is a vulnerability of currently unknown severity. ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.. EPSS estimates a 0.97% chance of exploitation in the next 30 days.

Description

ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.

Metrics

EPSS Probability
0.97%

57.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
ZyxelZywall 110 FirmwareAll versions
ZyxelZywall 1100 FirmwareAll versions
ZyxelZywall 310 FirmwareAll versions
ZyxelZywall Vpn 50 FirmwareAll versions
ZyxelZywall Vpn 100 FirmwareAll versions
ZyxelZywall Vpn 300 FirmwareAll versions
ZyxelUsg 20w FirmwareAll versions
ZyxelUsg 40 FirmwareAll versions
ZyxelUsg 40w FirmwareAll versions
ZyxelUsg 60 FirmwareAll versions
ZyxelUsg 60w FirmwareAll versions
ZyxelUsg 110 FirmwareAll versions
ZyxelUsg 2200-Vpn FirmwareAll versions
ZyxelUsg 310 FirmwareAll versions
ZyxelUsg 1100 FirmwareAll versions
ZyxelUsg 1900 FirmwareAll versions
ZyxelUsg 20w-Vpn FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-9129?
ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.
How severe is CVE-2018-9129?
Severity scoring for CVE-2018-9129 is pending analysis. The EPSS model estimates a 0.97% probability of exploitation in the next 30 days.
How do I fix CVE-2018-9129?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-9129?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST