PT-2023-8707 · Zyxel · Zyxel Atp Series+1

·

CVE-2023-6397

·

Published

2023-11-30

·

Updated

2025-01-21

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Zyxel ATP series versions 4.32 through 5.37 Patch 1 Zyxel USG FLEX series versions 4.50 through 5.37 Patch 1
Description A null pointer dereference issue in the Anti-Malware feature of Zyxel ATP and USG FLEX series firmware could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host. This issue is related to pointer dereference errors and can be exploited by a remote attacker to cause a denial of service.
Recommendations For Zyxel ATP series versions 4.32 through 5.37 Patch 1, consider disabling the Anti-Malware feature until a patch is available. For Zyxel USG FLEX series versions 4.50 through 5.37 Patch 1, consider disabling the Anti-Malware feature until a patch is available. As a temporary workaround, avoid using the Anti-Malware feature in the affected firmware versions until the issue is resolved.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01641
CVE-2023-6397

Affected Products

Zyxel Atp Series
Zyxel Usg Flex Series