Buffer Overflow Vulnerability in Zyxel ATP and USG FLEX Series Firmware
CVE-2023-4397
4.4MEDIUM
Key Information:
- Vendor
- Zyxel
- Status
- Vendor
- CVE Published:
- 28 November 2023
Summary
A buffer overflow vulnerability exists in the Zyxel ATP series and USG FLEX series firmware version 5.37. This flaw enables an authenticated local attacker with administrative privileges to exploit the vulnerability by executing specific Command Line Interface (CLI) commands containing crafted strings. The successful exploitation may lead to denial-of-service (DoS) conditions on the affected device, compromising the integrity and availability of the network services.
Affected Version(s)
USG FLEX 50(W) series firmware 5.37
ATP series firmware 5.37
USG FLEX series firmware 5.37
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved