{"cvss":9.8,"datePublished":"2023-05-31","dateUpdated":"2023-05-31","description":"Zyxel ATP, USG FLEX, VPN, and ZyWALL/USG firewalls allow for improper error message handling which could allow an unauthenticated attacker to execute OS commands remotely by sending crafted packets to an affected device.","dueDate":"2023-06-21","id":"CVE-2023-28771","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls;   https://nvd.nist.gov/vuln/detail/CVE-2023-28771","product":"Multiple Firewalls","requiredAction":"Apply updates per vendor instructions.","severity":"CRITICAL","source":"cisa_known_exploited","title":"Zyxel Multiple Firewalls OS Command Injection Vulnerability","vendor":"Zyxel"}