Description
A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmware version 6.50(ABTG.2) and earlier versions, WAC500 firmware version 6.50(ABVS.0) and earlier versions, and WAX510D firmware version 6.50(ABTF.2) and earlier versions, which could allow a remote authenticated attacker to retrieve encrypted information of the administrator on an affected device.
Published: 2023-04-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-27020 A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmware version 6.50(ABTG.2) and earlier versions, WAC500 firmware version 6.50(ABVS.0) and earlier versions, and WAX510D firmware version 6.50(ABTF.2) and earlier versions, which could allow a remote authenticated attacker to retrieve encrypted information of the administrator on an affected device.
History

No history.

Subscriptions

Zyxel Atp100 Atp100 Firmware Atp100w Atp100w Firmware Atp200 Atp200 Firmware Atp500 Atp500 Firmware Atp700 Atp700 Firmware Atp800 Atp800 Firmware Nap203 Nap203 Firmware Nap303 Nap303 Firmware Nap353 Nap353 Firmware Nwa110ax Nwa110ax Firmware Nwa1123-ac-pro Nwa1123-ac-pro Firmware Nwa1123-ac Hd Nwa1123-ac Hd Firmware Nwa1123acv3 Nwa1123acv3 Firmware Nwa210ax Nwa210ax Firmware Nwa220ax-6e Nwa220ax-6e Firmware Nwa50ax Nwa50ax-pro Nwa50ax-pro Firmware Nwa50ax Firmware Nwa5123-ac Hd Nwa5123-ac Hd Firmware Nwa55axe Nwa55axe Firmware Nwa90ax Nwa90ax-pro Nwa90ax-pro Firmware Nwa90ax Firmware Usg20-vpn Usg20-vpn Firmware Usg 20w-vpn Usg 20w-vpn Firmware Usg Flex 100 Usg Flex 100 Firmware Usg Flex 100w Usg Flex 100w Firmware Usg Flex 200 Usg Flex 200 Firmware Usg Flex 50 Usg Flex 500 Usg Flex 500 Firmware Usg Flex 50 Firmware Usg Flex 50w Usg Flex 50w Firmware Usg Flex 700 Usg Flex 700 Firmware Vpn100 Vpn1000 Vpn1000 Firmware Vpn100 Firmware Vpn300 Vpn300 Firmware Vpn50 Vpn50 Firmware Wac500 Wac500 Firmware Wac500h Wac500h Firmware Wac5302d-sv2 Wac5302d-sv2 Firmware Wac6103d-i Wac6103d-i Firmware Wac6303d-s Wac6303d-s Firmware Wac6502d-e Wac6502d-e Firmware Wac6502d-s Wac6502d-s Firmware Wac6503d-s Wac6503d-s Firmware Wac6552d-s Wac6552d-s Firmware Wac6553d-e Wac6553d-e Firmware Wax510d Wax510d Firmware Wax610d Wax610d Firmware Wax620d-6e Wax620d-6e Firmware Wax630s Wax630s Firmware Wax640s-6e Wax640s-6e Firmware Wax650s Wax650s Firmware Wax655e Wax655e Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2025-02-12T16:01:35.920Z

Reserved: 2023-01-10T00:00:00.000Z

Link: CVE-2023-22918

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-04-24T18:15:09.027

Modified: 2024-11-21T07:45:38.940

Link: CVE-2023-22918

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses