PT-2002-1000 · Zyxel · Zywall 10+1
Published
2002-03-11
·
Updated
2018-08-13
·
CVE-2002-0438
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
ZyXEL ZyWALL USG 300 (affected versions not specified)
ZyXEL ZyWALL 10 versions prior to 3.50
Description
The issue allows a remote attacker to cause a denial of service by sending a specially crafted ARP packet, which can disable the LAN interface of the firewall. This is achieved by sending an ARP packet with the firewall's IP address and an incorrect MAC address.
Recommendations
For ZyXEL ZyWALL 10 versions prior to 3.50, update to version 3.50 or later to resolve the issue.
For ZyXEL ZyWALL USG 300, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zywall 10
Zywall Usg 300