LAN-based Attacker Could Cause DoS Conditions by Downloading Crafted RAR File
CVE-2023-6397
Summary
A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feature enabled.
Affected Version(s)
ATP series firmware version 4.32 through 5.37 Patch 1
USG FLEX series firmware version 4.50 through 5.37 Patch 1
Get notified when SecurityVulnerability.io launches alerting đź””
Well keep you posted 📧
News Articles
![favicon image](https://securityonline.info/wp-content/uploads/2017/03/cropped-white-hat-icon-9-1-150x150.png)
Zyxel Security Vulnerabilities: DoS, Command Injection & More
Zyxel’s recent security advisory spotlights multiple vulnerabilities present in select firewall and access point models. Failure to take immediate action could leave these devices open to severe security risks. Vulnerability Breakdown CVE-2023-6397 (Firewalls): Potential denial-of-service...
1 year ago
References
CVSS V3.1
Timeline
- đź“°
First article discovered by securityonline.info
Vulnerability published
Vulnerability Reserved