Zyxel GS1900-48 switch vulnerable to buffer overflow DoS attack
CVE-2024-8882

4.5MEDIUM

Key Information:

Vendor
Zyxel
Vendor
CVE Published:
12 November 2024

Summary

A buffer overflow vulnerability exists in the CGI program of the Zyxel GS1900-48 switch, specifically in firmware version V2.80(AAHN.1)C0 and earlier. This vulnerability may be exploited by an authenticated attacker with administrator privileges on a LAN. By sending a specially crafted URL, the attacker could potentially trigger denial of service conditions, impacting the availability and functionality of the device. Addressing this vulnerability is essential to maintain the integrity and security of your network.

Affected Version(s)

GS1900-48 firmware <= V2.80(AAHN.1)C0

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.