PT-2002-1000 · Zyxel · Zywall 10+1

Published

2002-03-11

·

Updated

2018-08-13

·

CVE-2002-0438

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ZyXEL ZyWALL USG 300 (affected versions not specified) ZyXEL ZyWALL 10 versions prior to 3.50
Description The issue allows a remote attacker to cause a denial of service by sending a specially crafted ARP packet, which can disable the LAN interface of the firewall. This is achieved by sending an ARP packet with the firewall's IP address and an incorrect MAC address.
Recommendations For ZyXEL ZyWALL 10 versions prior to 3.50, update to version 3.50 or later to resolve the issue. For ZyXEL ZyWALL USG 300, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2014-00046
CVE-2002-0438

Affected Products

Zywall 10
Zywall Usg 300