SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-43393

An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0, which could allow an unauthenticated attacker to corrupt the contents of the memory and result in a…

HIGH 8.2EPSS 0.56%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0, which could allow an unauthenticated attacker to corrupt the contents of the memory and result in a denial-of-service (DoS) condition on a vulnerable device.

CVSS 3.1
8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
EPSS
0.56% probability · 45th percentile
CISA KEV
Not listed
Weakness
CWE-754
Affected
zyxel/gs1350-6hp firmware · zyxel/gs1350-12hp firmware · zyxel/gs1350-18hp firmware · zyxel/gs1350-26hp firmware · zyxel/gs1915-8 firmware · zyxel/gs1915-8ep firmware · zyxel/gs1915-24e firmware · zyxel/gs1915-24ep firmware · zyxel/gs1920-24v2 firmware · zyxel/gs1920-48v2 firmware · zyxel/gs1920-24hpv2 firmware · zyxel/gs1920-48hpv2 firmware · zyxel/gs2220-10 firmware · zyxel/gs2220-28 firmware · zyxel/gs2220-50 firmware · zyxel/gs2220-10hp firmware · zyxel/gs2220-28hp firmware · zyxel/gs2220-50hp firmware · zyxel/xgs1930-28 firmware · zyxel/xgs1930-28hp firmware · +25 more
Source
security@zyxel.com.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.