CVE-2023-4398

An integer overflow vulnerability in the source code of the QuickSec IPSec toolkit used in the VPN feature of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, and VPN series firmware versions 4.30 through 5.37, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions on an affected device by sending a crafted IKE packet.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
zyxelzld
4.32 ≤
𝑥
≤ 5.37
zyxelzld
4.50 ≤
𝑥
≤ 5.37
zyxelzld
4.16 ≤
𝑥
≤ 5.37
zyxelzld
4.30 ≤
𝑥
≤ 5.37
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
zyxelatp_firmware
4.32 ≤
𝑥
≤ 5.37
ADP
zyxelusg_flex_firmware
4.50 ≤
𝑥
≤ 5.37
ADP
zyxelusg_flex_50w_firmware
4.16 ≤
𝑥
≤ 5.37
ADP
zyxelusg20w-vpn_firmware
4.16 ≤
𝑥
≤ 5.37
ADP
zyxelvpn_firmware
5.30 ≤
𝑥
≤ 5.37
ADP