Zyxel GS1900-48 switch vulnerable to buffer overflow DoS attack

CVE-2024-8882

4.5MEDIUM

Key Information

Vendor
Zyxel
Status
Gs1900-48 Firmware
Vendor
CVE Published:
12 November 2024

Summary

A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to cause denial of service (DoS) conditions via a crafted URL.

Affected Version(s)

GS1900-48 firmware = <= V2.80(AAHN.1)C0

References

CVSS V3.1

Score:
4.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.