CVE-2023-4397
4.4
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Exploitability: 0.8 / Impact: 3.6
Source: security@zyxel.com.tw (Secondary)
Description
A buffer overflow vulnerability in the Zyxel ATP series firmware version 5.37, USG FLEX series firmware version 5.37, USG FLEX 50(W) series firmware version 5.37, and USG20(W)-VPN series firmware version 5.37, could allow an authenticated local attacker with administrator privileges to cause denial-of-service (DoS) conditions by executing the CLI command with crafted strings on an affected device.
Affected (1)
Configuration A
| Running on/with | Platform Versions |
|---|---|
Zyxel Atp100 | All versions |
Zyxel Atp100w | All versions |
Zyxel Atp200 | All versions |
Zyxel Atp500 | All versions |
Zyxel Atp700 | All versions |
Zyxel Atp800 | All versions |
Configuration B
| Running on/with | Platform Versions |
|---|---|
Zyxel Usg Flex 100 | All versions |
Zyxel Usg Flex 100w | All versions |
Zyxel Usg Flex 200 | All versions |
Zyxel Usg Flex 50 | All versions |
Zyxel Usg Flex 500 | All versions |
Zyxel Usg Flex 50w | All versions |
Zyxel Usg Flex 700 | All versions |
References (2)
Source: security@zyxel.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.