CVE-2023-27990: XSS
The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker with administrator privileges to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed when the user visits the Logs page of the GUI on the device.
Other sources
The XSS vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker with administrator privileges to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed when the user visits the Logs page of the GUI on the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27990?
The severity of CVE-2023-27990 is medium with a severity value of 4.8.
Which software versions are affected by CVE-2023-27990?
CVE-2023-27990 affects Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35.
What is the Common Weakness Enumeration (CWE) of CVE-2023-27990?
The Common Weakness Enumeration (CWE) of CVE-2023-27990 is CWE-79.
How can I fix CVE-2023-27990?
To fix CVE-2023-27990, it is recommended to update to a firmware version that is not vulnerable. Refer to the vendor's security advisory for more information.
Where can I find more information about CVE-2023-27990?
You can find more information about CVE-2023-27990 in the vendor's security advisory at https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-xss-vulnerability-and-post-authentication-command-injection-vulnerability-in-firewalls