cbcvebase.
CVE-2023-6397
published 2024-02-20

CVE-2023-6397: A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50…

medium5.3CVSS 3.1
AVAACHPRNUINSUCNINAH
A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feature enabled.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
zyxelatp100_firmware
zyxelatp100_firmware>= 4.32 < 5.375.37
zyxelatp100w_firmware
zyxelatp100w_firmware>= 4.32 < 5.375.37
zyxelatp200_firmware
zyxelatp200_firmware>= 4.32 < 5.375.37
zyxelatp500_firmware
zyxelatp500_firmware>= 4.32 < 5.375.37
zyxelatp700_firmware
zyxelatp700_firmware>= 4.32 < 5.375.37
zyxelatp800_firmware
zyxelatp800_firmware>= 4.32 < 5.375.37
zyxelatp_series_firmware
zyxelusg_flex_100_firmware
zyxelusg_flex_100_firmware>= 4.50 < 5.375.37
zyxelusg_flex_100ax_firmware
zyxelusg_flex_100ax_firmware>= 4.50 < 5.375.37
zyxelusg_flex_100h_firmware
zyxelusg_flex_100h_firmware>= 4.50 < 5.375.37
zyxelusg_flex_100w_firmware
zyxelusg_flex_100w_firmware>= 4.50 < 5.375.37
zyxelusg_flex_200_firmware
zyxelusg_flex_200_firmware>= 4.50 < 5.375.37
zyxelusg_flex_200h_firmware
zyxelusg_flex_200h_firmware>= 4.50 < 5.375.37