Attackers Can Cause DoS Conditions with Targeted Packets Against Zyxel Devices
CVE-2024-42058
7.5HIGH
Key Information:
- Vendor
Zyxel
- Status
- Vendor
- CVE Published:
- 3 September 2024
What is CVE-2024-42058?
A null pointer dereference vulnerability exists in the firmware of various Zyxel firewall products, including the ATP series and the USG FLEX series. This flaw allows unauthenticated attackers to send specially crafted packets to the affected devices, potentially leading to denial-of-service (DoS) conditions. Devices running the specified firmware versions are susceptible to disruptions, underlining the importance of prompt updates and patches to mitigate the risks associated with this vulnerability.
Affected Version(s)
ATP series firmware versions V4.32 through V5.38
USG FLEX 50(W) series firmware versions V5.20 through V5.38
USG FLEX series firmware versions V4.50 through V5.38