PT-2023-2585 · Zyxel · Zyxel Nbg-418N

Toni Koivunen

·

Publicado

2023-01-10

·

Atualizado

2023-05-06

·

CVE-2023-22924

CVSS v2.0

6.3

Média

VetorAV:N/AC:M/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Zyxel NBG-418N v2 versions prior to V1.00(AARP.14)C0
Description A buffer overflow vulnerability could allow a remote authenticated attacker with administrator privileges to cause denial-of-service (DoS) conditions by executing crafted CLI commands on a vulnerable device. The vulnerability is related to the lack of input size validation, which can be exploited by a remote attacker to disrupt the service.
Recommendations For Zyxel NBG-418N v2 versions prior to V1.00(AARP.14)C0, update the firmware to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the CLI interface to minimize the risk of exploitation. Avoid executing crafted CLI commands on the vulnerable device until the issue is resolved. At the moment, there is no information about additional mitigation measures.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02401
CVE-2023-22924

Produtos afetados

Zyxel Nbg-418N