CVE-2024-7203
NixOS vulnerability analysis and mitigation

Overview

A post-authentication command injection vulnerability was discovered in Zyxel ATP series firmware versions V4.60 through V5.38 and USG FLEX series firmware versions V4.60 through V5.38. This vulnerability is tracked as CVE-2024-7203 and was disclosed on September 2, 2024. The affected systems include Zyxel ATP series and USG FLEX series firewalls running the specified firmware versions (Vendor Advisory).

Technical details

The vulnerability is classified as a command injection flaw (CWE-78) that allows authenticated attackers with administrator privileges to execute operating system commands on affected devices by executing crafted CLI commands. The vulnerability has received a CVSS v3.1 base score of 7.2 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

If exploited, this vulnerability allows an authenticated attacker with administrator privileges to execute operating system commands on the affected device. This could potentially lead to complete system compromise, including unauthorized access to sensitive information, system modification, and service disruption (Vendor Advisory).

Mitigation and workarounds

Zyxel has released firmware version V5.39 to address this vulnerability. Users of affected devices are strongly advised to upgrade to the patched version. The fix is available for both ATP series and USG FLEX series devices (Vendor Advisory).

Community reactions

The vulnerability was discovered and reported by Alessandro Sgreccia and Manuel Roccon from HackerHood, demonstrating ongoing security research efforts in network device security (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
David EstlickCISO
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
Adam FletcherChief Security Officer
“We know that if Wiz identifies something as critical, it actually is.”
Greg PoniatowskiHead of Threat and Vulnerability Management