CVE-2023-5797: Medium severity zyxel zld firmware vulnerability
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series firmware versions 4.30 through 5.37, NWA50AX firmware version 6.29(ABYW.2), WAC500 firmware version 6.65(ABVS.1), WAX300H firmware version 6.60(ACHF.1), and WBE660S firmware version 6.65(ACGG.1), could allow an authenticated local attacker to access the administrator’s logs on an affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5797?
The severity of CVE-2023-5797 is classified as high, due to improper privilege management risks.
How do I fix CVE-2023-5797?
To fix CVE-2023-5797, users should update their Zyxel ATP, USG FLEX, and other affected firmware to the latest patched versions provided by Zyxel.
What are the affected firmware versions for CVE-2023-5797?
CVE-2023-5797 affects Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, and related firmware from multiple Zyxel products.
What types of devices are impacted by CVE-2023-5797?
CVE-2023-5797 impacts devices including Zyxel ATP firewalls, USG FLEX series firewalls, and other related network security appliances.
Is there a workaround for CVE-2023-5797?
Currently, the recommended action for CVE-2023-5797 is to apply the firmware updates as they serve as the most effective solution.