PT-2023-4399 · Zyxel · Zyxel Xs1930-10 +2

Published

2023-08-14

·

Updated

2023-08-21

·

CVE-2023-28768

CVSS v3.1
6.5
VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Name of the Vulnerable Software and Affected Versions:

Zyxel XGS2220-30 firmware version V4.80(ABXN.1)

Zyxel XMG1930-30 firmware version V4.80(ACAR.1)

Zyxel XS1930-10 firmware version V4.80(ABQE.1)

Description:

The issue is related to improper frame handling in the firmware of certain Zyxel switches, which could allow an unauthenticated LAN-based attacker to cause denial-of-service (DoS) conditions by sending crafted frames to an affected switch. This is due to insufficient handling of exceptional states.

Recommendations:

For Zyxel XGS2220-30 firmware version V4.80(ABXN.1), update the firmware to a version that fixes the improper frame handling issue.

For Zyxel XMG1930-30 firmware version V4.80(ACAR.1), update the firmware to a version that fixes the improper frame handling issue.

For Zyxel XS1930-10 firmware version V4.80(ABQE.1), update the firmware to a version that fixes the improper frame handling issue.

As a temporary workaround, consider restricting access to the affected switches to minimize the risk of exploitation.

Fix

Improper Handling of Exceptional Conditions

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2023-04744
CVE-2023-28768

Affected Products

Zyxel Xgs2220-30
Zyxel Xmg1930-30
Zyxel Xs1930-10