Known vulnerabilities in ZyWALL

Software: ZyWALL
Software CPE: cpe:2.3:a:zyxel_communications_corp:zywall:*:*:*:*:*:*:*:*
Total vulnerabilities: 12
Public exploits: 3
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ZyWALL ZyWALL is affected by 12 known vulnerabilities: 5 high, 2 medium, 5 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU76515 - Memory corruption
CVE-2023-33010
CWE-119 High
No
Exploited
4.73 Patch 2 25.05.2023 SB2023052525
#VU76514 - Memory corruption
CVE-2023-33009
CWE-119 High
No
Exploited
4.73 Patch 2 25.05.2023 SB2023052525
#VU75461 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-28771
CWE-78 High
Available
Exploited
4.73 Patch 1 25.04.2023 SB2023042507
#VU71972 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-38547
CWE-78 Medium
No
No
4.73 07.02.2023 SB2023020704
#VU69914 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-40603
CWE-79 Low
No
No
4.73 06.12.2022 SB2022120602
#VU65413 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-2030
CWE-22 Medium
No
No
4.72 week28 19.07.2022 SB2022071902
#VU65410 - Permissions, Privileges, and Access Controls
CVE-2022-30526
CWE-264 Low
Available
No
4.72 week28 19.07.2022 SB2022071902
#VU63569 - Improper Access Control
CVE-2022-0910
CWE-284 High
No
No
4.72 24.05.2022 SB2022052406
#VU63562 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-26532
CWE-78 Low
No
No
4.72 24.05.2022 SB2022052406
#VU63561 - Improper input validation
CVE-2022-26531
CWE-20 Low
Available
No
4.72 24.05.2022 SB2022052406
#VU63555 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-0734
CWE-79 Low
No
No
4.72 24.05.2022 SB2022052406
#VU61723 - Improper Authentication
CVE-2022-0342
CWE-287 High
No
No
4.71 30.03.2022 SB2022033003