CVE-2023-22918

MEDIUMCVSS 6.5/10EPSS 0.77%

Last modified

CVE-2023-22918 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmware version 6.50(ABTG.2) and earlier versions, WAC500 firmware version 6.50(ABVS.0) and earlier versions, and WAX510D firmware version 6.50(ABTF.2) and earlier versions, which could allow a remote authenticated attacker to retrieve encrypted information of the administrator on an affected device.. EPSS estimates a 0.77% chance of exploitation in the next 30 days.

Description

A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmware version 6.50(ABTG.2) and earlier versions, WAC500 firmware version 6.50(ABVS.0) and earlier versions, and WAX510D firmware version 6.50(ABTF.2) and earlier versions, which could allow a remote authenticated attacker to retrieve encrypted information of the administrator on an affected device.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.77%

51.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ZyxelAtp200 Firmware>= 4.32, < 5.36
ZyxelAtp100 Firmware>= 4.32, < 5.36
ZyxelAtp700 Firmware>= 4.32, < 5.36
ZyxelAtp500 Firmware>= 4.32, < 5.36
ZyxelAtp100w Firmware>= 4.32, < 5.36
ZyxelAtp800 Firmware>= 4.32, < 5.36
ZyxelUsg Flex 100 Firmware>= 4.50, < 5.36
ZyxelUsg Flex 50 Firmware>= 4.50, < 5.36
ZyxelUsg Flex 200 Firmware>= 4.50, < 5.36
ZyxelUsg Flex 500 Firmware>= 4.50, < 5.36
ZyxelUsg Flex 700 Firmware>= 4.50, < 5.36
ZyxelUsg Flex 100w Firmware>= 4.50, < 5.36
ZyxelUsg 20w-Vpn Firmware>= 4.16, < 5.36
ZyxelUsg Flex 50w Firmware>= 4.16, < 5.36
ZyxelUsg20-Vpn Firmware>= 4.30, < 5.36
ZyxelVpn100 Firmware>= 4.30, < 5.36
ZyxelVpn1000 Firmware>= 4.30, < 5.36
ZyxelVpn300 Firmware>= 4.30, < 5.36
ZyxelVpn50 Firmware>= 4.30, < 5.36
ZyxelNap203 Firmware<= 6.28\(abfa.0\)
ZyxelNap303 Firmware<= 6.28\(abex.0\)
ZyxelNap353 Firmware<= 6.28\(abey.0\)
ZyxelNwa110ax Firmware<= 6.50\(abtg.2\)
ZyxelNwa1123-Ac Hd Firmware<= 6.25\(abin.9\)
ZyxelNwa1123-Ac-Pro Firmware<= 6.28\(abhd.0\)
ZyxelNwa1123acv3 Firmware<= 6.50\(abvt.0\)
ZyxelNwa210ax Firmware<= 6.50\(abtd.2\)
ZyxelNwa220ax-6e Firmware<= 6.50\(acco.2\)
ZyxelNwa50ax Firmware<= 6.55\(acge.1\)
ZyxelNwa50ax-Pro Firmware<= 6.50\(acge.0\)
ZyxelNwa5123-Ac Hd Firmware<= 6.25\(abim.9\)
ZyxelNwa55axe Firmware<= 6.29\(abzl.1\)
ZyxelNwa90ax Firmware<= 6.29\(accv.1\)
ZyxelNwa90ax-Pro Firmware<= 6.50\(acgf.0\)
ZyxelWac500 Firmware<= 6.50\(abvs.0\)
ZyxelWac500h Firmware<= 6.50\(abwa.0\)
ZyxelWac5302d-Sv2 Firmware<= 6.25\(abvz.9\)
ZyxelWac6103d-I Firmware<= 6.28\(aaxh.0\)
ZyxelWac6303d-S Firmware<= 6.25\(abgl.9\)
ZyxelWac6502d-E Firmware<= 6.28\(aasd.0\)
ZyxelWac6502d-S Firmware<= 6.28\(aase.0\)
ZyxelWac6503d-S Firmware<= 6.28\(aasf.0\)
ZyxelWac6552d-S Firmware<= 6.28\(abio.0\)
ZyxelWac6553d-E Firmware<= 6.28\(aasg.0\)
ZyxelWax510d Firmware<= 6.50\(abtf.2\)
ZyxelWax610d Firmware<= 6.50\(abte.2\)
ZyxelWax620d-6e Firmware<= 6.50\(accn.2\)
ZyxelWax630s Firmware<= 6.50\(abzd.2\)
ZyxelWax640s-6e Firmware<= 6.50\(accm.2\)
ZyxelWax650s Firmware<= 6.50\(abrm.2\)

Showing 50 of 51 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-22918?
A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmware version 6.50(ABTG.2) and earlier versions, WAC500 firmware version 6.50(ABVS.0) and earlier versions, and WAX510D firmware version 6.50(ABTF.2) and earlier versions, which could allow a remote authenticated attacker to retrieve encrypted information of the administrator on an affected device.
How severe is CVE-2023-22918?
CVE-2023-22918 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.77% probability of exploitation in the next 30 days.
How do I fix CVE-2023-22918?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-22918?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST