Known vulnerabilities in USG20W-VPN 5.36 Patch 2

Software: USG20W-VPN
Version: 5.36 Patch 2
Software CPE: cpe:2.3:h:zyxel_communications_corp:usg20w-vpn:*:*:*:*:*:*:*:*
Total vulnerabilities: 5
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.7

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting USG20W-VPN version 5.36 Patch 2 USG20W-VPN 5.36 Patch 2 is affected by 5 vulnerabilities: 4 medium, 1 low Critical High Medium Low

Vulnerabilities (5)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU78352 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-34141
CWE-78 Medium
No
No
5.37 18.07.2023 SB2023071819
#VU78351 - Memory corruption
CVE-2023-34140
CWE-119 Low
No
No
5.37 18.07.2023 SB2023071819
#VU78349 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-34138
CWE-78 Medium
No
No
5.37 18.07.2023 SB2023071819
#VU78348 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-33012
CWE-78 Medium
Public exploit available
No
5.37 18.07.2023 SB2023071819
#VU78347 - Use of Externally-Controlled Format String
CVE-2023-33011
CWE-134 Medium
No
No
5.37 18.07.2023 SB2023071819