CVE-2023-27991: OS Command Injection
The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker to execute some OS commands remotely.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-27991?
CVE-2023-27991 is a post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35.
Which Zyxel products are affected by CVE-2023-27991?
Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series.
What is the severity of CVE-2023-27991?
CVE-2023-27991 has a severity value of 8.8 (high).
How can I fix CVE-2023-27991?
To fix CVE-2023-27991, you should update the affected firmware versions to 5.36 for ATP series and USG FLEX series, and to 4.30 for USG20(W)-VPN and VPN series.
Where can I find more information about CVE-2023-27991?
You can find more information about CVE-2023-27991 at the following link: [Zyxel Security Advisory](https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-xss-vulnerability-and-post-authentication-command-injection-vulnerability-in-firewalls)