PT-2023-4399 · Zyxel · Zyxel Xs1930-10+2

Published

2023-08-14

·

Updated

2023-08-21

·

CVE-2023-28768

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Zyxel XGS2220-30 firmware version V4.80(ABXN.1) Zyxel XMG1930-30 firmware version V4.80(ACAR.1) Zyxel XS1930-10 firmware version V4.80(ABQE.1)
Description The issue is related to improper frame handling in the firmware of certain Zyxel switches, which could allow an unauthenticated LAN-based attacker to cause denial-of-service (DoS) conditions by sending crafted frames to an affected switch. This is due to insufficient handling of exceptional states.
Recommendations For Zyxel XGS2220-30 firmware version V4.80(ABXN.1), update the firmware to a version that fixes the improper frame handling issue. For Zyxel XMG1930-30 firmware version V4.80(ACAR.1), update the firmware to a version that fixes the improper frame handling issue. For Zyxel XS1930-10 firmware version V4.80(ABQE.1), update the firmware to a version that fixes the improper frame handling issue. As a temporary workaround, consider restricting access to the affected switches to minimize the risk of exploitation.

Fix

Improper Handling of Exceptional Conditions

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2023-04744
CVE-2023-28768

Affected Products

Zyxel Xgs2220-30
Zyxel Xmg1930-30
Zyxel Xs1930-10