CVE-2018-9129 describes a Bleichenbacher vulnerability in the Internet Key Exchange (IKE) handshake implementation of ZyXEL ZyWALL/USG series devices, impacting their IPsec VPN connections. This medium-severity vulnerability (CVSS 5.9) allows an unauthenticated attacker to achieve a high integrity impact over the network with high attack complexity, though it has no confidentiality or availability impact. While not listed in the KEV catalog and with no known public exploits or Metasploit modules, it has garnered significant community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:zywall_110_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:zywall_1100_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:zywall_310_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:zywall_vpn_50_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:zyxel:zywall_vpn_100_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.