CVE-2023-22918: Medium severity zyxel atp200 firmware vulnerability
A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmware version 6.50(ABTG.2) and earlier versions, WAC500 firmware version 6.50(ABVS.0) and earlier versions, and WAX510D firmware version 6.50(ABTF.2) and earlier versions, which could allow a remote authenticated attacker to retrieve encrypted information of the administrator on an affected device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-22918?
CVE-2023-22918 has been classified as a medium severity vulnerability.
How can I fix CVE-2023-22918?
To mitigate CVE-2023-22918, upgrade affected Zyxel devices to the latest firmware versions provided by Zyxel.
Which Zyxel products are affected by CVE-2023-22918?
CVE-2023-22918 affects multiple Zyxel products including ATP series, USG FLEX series, and USG 20W-VPN firmware versions from 4.32 to 5.35.
What type of vulnerability is CVE-2023-22918?
CVE-2023-22918 is a post-authentication information exposure vulnerability in Zyxel CGI programs.
Is CVE-2023-22918 actively being exploited?
As of now, there is no reported active exploitation of CVE-2023-22918.