« Volver al listado

CVE-2024-11667

Estado: AnalizadaCrítica (9.8)⚠ Explotación activa

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CISA KEV — explotada activamente

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector AV:N/PR:N/UI:N indica acceso remoto sin autenticación (T1190). CWE-22 (directory traversal) permite lectura/escritura de archivos (T1005, T1565.001). KEV activo y uso en ransomware confirman explotación en wild.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-11667",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-11667",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-05T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@zyxel.com.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@zyxel.com.tw",
      "affectedData": [
        {
          "vendor": "Zyxel",
          "product": "ATP series firmware",
          "versions": [
            {
              "status": "affected",
              "version": "versions V5.00 through V5.38"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Zyxel",
          "product": "USG FLEX series firmware",
          "versions": [
            {
              "status": "affected",
              "version": "versions V5.00 through V5.38"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Zyxel",
          "product": "USG FLEX 50(W) series firmware",
          "versions": [
            {
              "status": "affected",
              "version": "versions V5.10 through V5.38"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Zyxel",
          "product": "USG20(W)-VPN series firmware",
          "versions": [
            {
              "status": "affected",
              "version": "versions V5.10 through V5.38"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:zyxel:usg_flex_100h_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_100hp_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_100w_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_200_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_200h_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_200hp_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_500_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_500h_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_500w_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_50ax_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_50_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_60ax_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_700_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_700h_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:usg_flex_firmware:-:*:*:*:*:*:*:*"
          ],
          "vendor": "zyxel",
          "product": "usg_flex_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "5.00",
              "versionType": "custom",
              "lessThanOrEqual": "5.38"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:zyxel:atp100_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:atp100w_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:atp500_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:atp700_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:atp800_firmware:-:*:*:*:*:*:*:*",
            "cpe:2.3:o:zyxel:atp_firmware:-:*:*:*:*:*:*:*"
          ],
          "vendor": "zyxel",
          "product": "atp_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "5.00",
              "versionType": "custom",
              "lessThanOrEqual": "5.38"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:zyxel:usg20-vpn_firmware:-:*:*:*:*:*:*:*"
          ],
          "vendor": "zyxel",
          "product": "usg20-vpn_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "5.10",
              "versionType": "custom",
              "lessThanOrEqual": "5.38"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:o:zyxel:usg_flex_50w_firmware:-:*:*:*:*:*:*:*"
          ],
          "vendor": "zyxel",
          "product": "usg_flex_50w_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "5.10",
              "lessThan": "5.38",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-11-27T10:15:04.210",
  "references": [
    {
      "url": "https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-27-2024",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@zyxel.com.tw"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-11667",
      "tags": [
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@zyxel.com.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series firmware versions V5.10 through V5.38 could allow an attacker to download or upload files via a crafted URL."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de directory traversal en la interfaz de administración web de las versiones de firmware de la serie Zyxel ATP V5.00 a V5.38, las versiones de firmware de la serie USG FLEX V5.00 a V5.38, las versiones de firmware de la serie USG FLEX 50(W) V5.10 a V5.38 y las versiones de firmware de la serie USG20(W)-VPN V5.10 a V5.38 podría permitir que un atacante descargue o cargue archivos a través de una URL manipulada específicamente."
    }
  ],
  "lastModified": "2026-08-05T05:16:40.797",
  "cisaActionDue": "2024-12-24",
  "cisaExploitAdd": "2024-12-03",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18B592F1-F584-4573-AD75-398CE03F6627",
              "versionEndIncluding": "5.38",
              "versionStartIncluding": "5.00"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:atp:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "788B28B2-E2EE-4D98-8862-15B121009B6E"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:atp100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7F7654A1-3806-41C7-82D4-46B0CD7EE53B"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:atp100w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "47398FD0-6C5E-4625-9EFD-DE08C9AB7DB2"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:atp200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D68A36FF-8CAF-401C-9F18-94F3A2405CF4"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:atp500:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2818E8AC-FFEE-4DF9-BF3F-C75166C0E851"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:atp700:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0B41F437-855B-4490-8011-DF59887BE6D5"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:atp800:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "66B99746-0589-46E6-9CBD-F38619AD97DC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18B592F1-F584-4573-AD75-398CE03F6627",
              "versionEndIncluding": "5.38",
              "versionStartIncluding": "5.00"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E4EDCC3C-8EE5-43D3-8739-34987F025DF2"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_100:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2B30A4C0-9928-46AD-9210-C25656FB43FB"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_100ax:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "03036815-04AE-4E39-8310-DA19A32CFA48"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_100w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D74ABA7E-AA78-4A13-A64E-C44021591B42"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_200:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F93B6A06-2951-46D2-A7E1-103D7318D612"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_50:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "646C1F07-B553-47B0-953B-DC7DE7FD0F8B"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_500:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "92C697A5-D1D3-4FF0-9C43-D27B18181958"
            },
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_700:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9D1396E3-731B-4D05-A3F8-F3ABB80D5C29"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBEE7B76-74EB-4570-9A5B-071BA9E36DB9",
              "versionEndIncluding": "5.38",
              "versionStartIncluding": "5.10"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:usg_flex_50w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "110A1CA4-0170-4834-8281-0A3E14FC5584"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBEE7B76-74EB-4570-9A5B-071BA9E36DB9",
              "versionEndIncluding": "5.38",
              "versionStartIncluding": "5.10"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:zyxel:usg_20w-vpn:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6BEA412F-3DA1-4E91-9C74-0666147DABCE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@zyxel.com.tw",
  "cisaRequiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
  "cisaVulnerabilityName": "Zyxel Multiple Firewalls Path Traversal Vulnerability"
}