Post-Authentication Command Injection Vulnerability Affects Zyxel ATP Series Firmware
CVE-2024-7203
7.2HIGH
Key Information:
- Vendor
- Zyxel
- Vendor
- CVE Published:
- 3 September 2024
Summary
A post-authentication command injection vulnerability exists in Zyxel ATP and USG FLEX series firmware that could allow an authenticated attacker with administrator privileges to execute arbitrary operating system commands. This vulnerability arises when a crafted command is executed within the command-line interface, potentially compromising the integrity and security of the affected devices. Users are advised to review their current firmware versions and apply necessary updates to mitigate potential risks.
Affected Version(s)
ATP series firmware versions V4.60 through V5.38
USG FLEX series firmware versions V4.60 through V5.38
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved