CVE-2023-27990

The cross-site scripting (XSS) vulnerability in Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker with administrator privileges to store malicious scripts in a vulnerable device. A successful XSS attack could then result in the stored malicious scripts being executed when the user visits the Logs page of the GUI on the device.

Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
ZyxelCNA
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
VendorProductVersion
zyxelatp200_firmware
4.32 ≤
𝑥
< 5.36
zyxelatp100_firmware
4.32 ≤
𝑥
< 5.36
zyxelatp700_firmware
4.32 ≤
𝑥
< 5.36
zyxelatp500_firmware
4.32 ≤
𝑥
< 5.36
zyxelatp100w_firmware
4.32 ≤
𝑥
< 5.36
zyxelatp800_firmware
4.32 ≤
𝑥
< 5.36
zyxelusg_flex_100_firmware
4.50 ≤
𝑥
< 5.36
zyxelusg_flex_50_firmware
4.50 ≤
𝑥
< 5.36
zyxelusg_flex_200_firmware
4.50 ≤
𝑥
< 5.36
zyxelusg_flex_500_firmware
4.50 ≤
𝑥
< 5.36
zyxelusg_flex_700_firmware
4.50 ≤
𝑥
< 5.36
zyxelusg_flex_100w_firmware
4.50 ≤
𝑥
< 5.36
zyxelusg_20w-vpn_firmware
4.16 ≤
𝑥
< 5.36
zyxelusg_flex_50w_firmware
4.16 ≤
𝑥
< 5.36
zyxelusg20-vpn_firmware
4.30 ≤
𝑥
< 5.36
zyxelvpn100_firmware
4.30 ≤
𝑥
< 5.36
zyxelvpn1000_firmware
4.30 ≤
𝑥
< 5.36
zyxelvpn300_firmware
4.30 ≤
𝑥
< 5.36
zyxelvpn50_firmware
4.30 ≤
𝑥
< 5.36
𝑥
= Vulnerable software versions