Vulnerability CVE-2023-6397


Published: 2024-02-20

Description:












A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the ??Anti-Malware? feature enabled.



Type:

CWE-476

(NULL Pointer Dereference)

 References:
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-firewalls-and-aps-02-20-2024

Copyright 2024, cxsecurity.com

 

Back to Top