Zyxel GS1900-48 switch vulnerable to buffer overflow DoS attack
CVE-2024-8882
4.5MEDIUM
Summary
A buffer overflow vulnerability exists in the CGI program of the Zyxel GS1900-48 switch, specifically in firmware version V2.80(AAHN.1)C0 and earlier. This vulnerability may be exploited by an authenticated attacker with administrator privileges on a LAN. By sending a specially crafted URL, the attacker could potentially trigger denial of service conditions, impacting the availability and functionality of the device. Addressing this vulnerability is essential to maintain the integrity and security of your network.
Affected Version(s)
GS1900-48 firmware <= V2.80(AAHN.1)C0
References
CVSS V3.1
Score:
4.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved