CVE-2022-43393
An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0, which could allow an unauthenticated attacker to corrupt the contents of the memory and result in a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0, which could allow an unauthenticated attacker to corrupt the contents of the memory and result in a denial-of-service (DoS) condition on a vulnerable device.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-754
- Affected
- zyxel/gs1350-6hp firmware · zyxel/gs1350-12hp firmware · zyxel/gs1350-18hp firmware · zyxel/gs1350-26hp firmware · zyxel/gs1915-8 firmware · zyxel/gs1915-8ep firmware · zyxel/gs1915-24e firmware · zyxel/gs1915-24ep firmware · zyxel/gs1920-24v2 firmware · zyxel/gs1920-48v2 firmware · zyxel/gs1920-24hpv2 firmware · zyxel/gs1920-48hpv2 firmware · zyxel/gs2220-10 firmware · zyxel/gs2220-28 firmware · zyxel/gs2220-50 firmware · zyxel/gs2220-10hp firmware · zyxel/gs2220-28hp firmware · zyxel/gs2220-50hp firmware · zyxel/xgs1930-28 firmware · zyxel/xgs1930-28hp firmware · +25 more
- Source
- security@zyxel.com.tw
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.