A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feature enabled
Published Feb 20, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.30%
Description
A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feature enabled.
Affected products
-
- Version version 4.32 through 5.37 Patch 1StatusaffectedConstraints-
- Version
-
- Version version 4.50 through 5.37 Patch 1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Zyxel | ATP series firmware | unaffected |
| ||||||
| Zyxel | USG FLEX series firmware | unaffected |
|
Configuration 1
- ≥ 4.32 · < 5.37
- 5.37
- 5.37
Configuration 2
- ≥ 4.32 · < 5.37
- 5.37
- 5.37
Configuration 3
- ≥ 4.32 · < 5.37
- 5.37
- 5.37
Configuration 4
- ≥ 4.32 · < 5.37
- 5.37
- 5.37
Configuration 5
- ≥ 4.32 · < 5.37
- 5.37
- 5.37
Configuration 6
- ≥ 4.32 · < 5.37
- 5.37
- 5.37
Configuration 7
- ≥ 4.50 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 8
- ≥ 4.50 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 9
- ≥ 4.50 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 10
- ≥ 4.50 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 11
- ≥ 4.50 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 12
- ≥ 4.50 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 13
- ≥ 4.50 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 14
- ≥ 4.50 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 15
- ≥ 4.50 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 16
- ≥ 4.50 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 17
- ≥ 4.50 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 18
- ≥ 4.50 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 19
- ≥ 4.50 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58634 Advisory
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-firewalls-and-aps-02-20-2024 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58634 | Advisory | |
| https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-firewalls-and-aps-02-20-2024 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.