Description












A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feature enabled.



Published: 2024-02-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-58634 A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feature enabled.
History

Tue, 21 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Zyxel
Zyxel atp100
Zyxel atp100 Firmware
Zyxel atp100w
Zyxel atp100w Firmware
Zyxel atp200
Zyxel atp200 Firmware
Zyxel atp500
Zyxel atp500 Firmware
Zyxel atp700
Zyxel atp700 Firmware
Zyxel atp800
Zyxel atp800 Firmware
Zyxel usg Flex 100
Zyxel usg Flex 100 Firmware
Zyxel usg Flex 100ax
Zyxel usg Flex 100ax Firmware
Zyxel usg Flex 100h
Zyxel usg Flex 100h Firmware
Zyxel usg Flex 100w
Zyxel usg Flex 100w Firmware
Zyxel usg Flex 200
Zyxel usg Flex 200 Firmware
Zyxel usg Flex 200h
Zyxel usg Flex 200h Firmware
Zyxel usg Flex 200hp
Zyxel usg Flex 200hp Firmware
Zyxel usg Flex 50
Zyxel usg Flex 500
Zyxel usg Flex 500 Firmware
Zyxel usg Flex 500h
Zyxel usg Flex 500h Firmware
Zyxel usg Flex 50 Firmware
Zyxel usg Flex 50w
Zyxel usg Flex 50w Firmware
Zyxel usg Flex 700
Zyxel usg Flex 700 Firmware
Zyxel usg Flex 700h
Zyxel usg Flex 700h Firmware
CPEs cpe:2.3:h:zyxel:atp100:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:atp100w:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:atp200:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:atp500:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:atp700:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:atp800:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_100:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_100ax:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_100h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_100w:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_200hp:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_500:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_500h:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_50:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_50w:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_700:-:*:*:*:*:*:*:*
cpe:2.3:h:zyxel:usg_flex_700h:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp100_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp100_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp100w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp100w_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp100w_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp200_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp200_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp500_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp500_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp700_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp700_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp700_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp800_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:atp800_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_100_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_100_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_100ax_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_100ax_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_100ax_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_100h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_100h_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_100h_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_100w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_100w_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_100w_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_200_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_200_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_200h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_200h_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_200h_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_200hp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_200hp_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_200hp_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_500_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_500_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_500h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_500h_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_500h_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_50_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_50_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_50w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_50w_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_50w_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_700_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_700_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_700_firmware:5.37:patch1:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_700h_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_700h_firmware:5.37:-:*:*:*:*:*:*
cpe:2.3:o:zyxel:usg_flex_700h_firmware:5.37:patch1:*:*:*:*:*:*
Vendors & Products Zyxel
Zyxel atp100
Zyxel atp100 Firmware
Zyxel atp100w
Zyxel atp100w Firmware
Zyxel atp200
Zyxel atp200 Firmware
Zyxel atp500
Zyxel atp500 Firmware
Zyxel atp700
Zyxel atp700 Firmware
Zyxel atp800
Zyxel atp800 Firmware
Zyxel usg Flex 100
Zyxel usg Flex 100 Firmware
Zyxel usg Flex 100ax
Zyxel usg Flex 100ax Firmware
Zyxel usg Flex 100h
Zyxel usg Flex 100h Firmware
Zyxel usg Flex 100w
Zyxel usg Flex 100w Firmware
Zyxel usg Flex 200
Zyxel usg Flex 200 Firmware
Zyxel usg Flex 200h
Zyxel usg Flex 200h Firmware
Zyxel usg Flex 200hp
Zyxel usg Flex 200hp Firmware
Zyxel usg Flex 50
Zyxel usg Flex 500
Zyxel usg Flex 500 Firmware
Zyxel usg Flex 500h
Zyxel usg Flex 500h Firmware
Zyxel usg Flex 50 Firmware
Zyxel usg Flex 50w
Zyxel usg Flex 50w Firmware
Zyxel usg Flex 700
Zyxel usg Flex 700 Firmware
Zyxel usg Flex 700h
Zyxel usg Flex 700h Firmware

Subscriptions

Zyxel Atp100 Atp100 Firmware Atp100w Atp100w Firmware Atp200 Atp200 Firmware Atp500 Atp500 Firmware Atp700 Atp700 Firmware Atp800 Atp800 Firmware Usg Flex 100 Usg Flex 100 Firmware Usg Flex 100ax Usg Flex 100ax Firmware Usg Flex 100h Usg Flex 100h Firmware Usg Flex 100w Usg Flex 100w Firmware Usg Flex 200 Usg Flex 200 Firmware Usg Flex 200h Usg Flex 200h Firmware Usg Flex 200hp Usg Flex 200hp Firmware Usg Flex 50 Usg Flex 500 Usg Flex 500 Firmware Usg Flex 500h Usg Flex 500h Firmware Usg Flex 50 Firmware Usg Flex 50w Usg Flex 50w Firmware Usg Flex 700 Usg Flex 700 Firmware Usg Flex 700h Usg Flex 700h Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Zyxel

Published:

Updated: 2024-08-02T08:28:21.794Z

Reserved: 2023-11-30T07:58:12.915Z

Link: CVE-2023-6397

cve-icon Vulnrichment

Updated: 2024-05-23T19:01:12.948Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-20T02:15:48.793

Modified: 2025-01-21T18:47:29.627

Link: CVE-2023-6397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses