A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1, and USG FLEX H series firmware versions from 1.10 through 1.10 Patch 1 could allow an authenticated IPSec VPN user to cause DoS conditions against the “deviceid” daemon by sending a crafted hostname to an affected device if it has the “Device Insight” feature enabled
Published Feb 20, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.65%
Description
A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1, and USG FLEX H series firmware versions from 1.10 through 1.10 Patch 1 could allow an authenticated IPSec VPN user to cause DoS conditions against the “deviceid” daemon by sending a crafted hostname to an affected device if it has the “Device Insight” feature enabled.
Affected products
-
Affected
- version 4.32 through 5.37 Patch 1
-
Affected
- version 4.16 through 5.37 Patch 1
-
Affected
- version 1.10 through 1.10 Patch 1
-
Affected
- version 4.50 through 5.37 Patch 1
-
Affected
- version 4.16 through 5.37 Patch 1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Zyxel | ATP series firmware | unaffected | Affected
|
| Zyxel | USG FLEX 50(W) series firmware | unaffected | Affected
|
| Zyxel | USG FLEX H series firmware | unaffected | Affected
|
| Zyxel | USG FLEX series firmware | unaffected | Affected
|
| Zyxel | USG20(W)-VPN series firmware | unaffected | Affected
|
Configuration 1
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Configuration 2
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Configuration 3
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Configuration 4
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Configuration 5
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Configuration 6
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Configuration 7
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 8
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 9
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 10
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 11
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 12
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 13
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 14
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 15
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 16
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 17
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 18
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 19
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 20
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Configuration 21
- ≥ 5.10 · < 5.37
- 5.37
- 5.37
Running on/with
- n/a
Configuration 22
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58636 Advisory
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-firewalls-and-aps-02-20-2024 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58636 | Advisory | |
| https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-firewalls-and-aps-02-20-2024 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data