First published: Wed Aug 15 2018(Updated: )
ZyXEL ZyWALL/USG series devices have a Bleichenbacher vulnerability in their Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel Zywall 110 Firmware | ||
Zyxel Zywall 110 | ||
Zyxel Zywall 1100 Firmware | ||
Zyxel Zywall 1100 | ||
Zyxel Zywall 310 Firmware | ||
Zyxel Zywall 310 | ||
Zyxel Zywall Vpn 50 Firmware | ||
Zyxel Zywall Vpn 50 | ||
Zyxel Zywall Vpn 100 Firmware | ||
Zyxel Zywall Vpn 100 | ||
Zyxel Zywall Vpn 300 Firmware | ||
Zyxel Zywall Vpn 300 | ||
Zyxel Usg 20w Firmware | ||
Zyxel Usg 20w | ||
Zyxel Usg 40 Firmware | ||
Zyxel Usg 40 | ||
Zyxel Usg 40w Firmware | ||
Zyxel Usg 40w | ||
Zyxel Usg 60 Firmware | ||
Zyxel Usg 60 | ||
Zyxel Usg 60w Firmware | ||
Zyxel Usg 60w | ||
Zyxel Usg 110 Firmware | ||
Zyxel Usg 110 | ||
Zyxel Usg 2200-vpn Firmware | ||
Zyxel Usg 2200-vpn | ||
Zyxel Usg 310 Firmware | ||
Zyxel Usg 310 | ||
Zyxel Usg 1100 Firmware | ||
Zyxel Usg 1100 | ||
Zyxel Usg 1900 Firmware | ||
Zyxel Usg 1900 | ||
Zyxel Usg 20w-vpn Firmware | ||
Zyxel Usg 20w-vpn |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9129 is a vulnerability in the Internet Key Exchange (IKE) handshake implementation used for IPsec based VPN connections in ZyXEL ZyWALL/USG series devices.
ZyXEL ZyWALL/USG series devices such as Zyxel Zywall 110, Zyxel Zywall 1100, Zyxel Zywall 310, Zyxel Zywall Vpn 50, Zyxel Zywall Vpn 100, Zyxel Zywall Vpn 300, Zyxel Usg 20w, Zyxel Usg 40, Zyxel Usg 40w, Zyxel Usg 60, Zyxel Usg 60w, Zyxel Usg 110, Zyxel Usg 2200-vpn, Zyxel Usg 310, Zyxel Usg 1100, Zyxel Usg 1900, and Zyxel Usg 20w-vpn are affected by CVE-2018-9129.
No, the ZyXEL devices mentioned in the previous question have been marked as not vulnerable to CVE-2018-9129.
CVE-2018-9129 has a severity rating of 5.9, which is considered medium.
To fix the CVE-2018-9129 vulnerability, it is recommended to update the firmware of your ZyXEL ZyWALL/USG series device to the latest version provided by ZyXEL.