SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-6397

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS)…

MEDIUM 5.3EPSS 0.30%

Does this matter?

Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.

Description

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feature enabled.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
0.30% probability · 23th percentile
CISA KEV
Not listed
Weakness
CWE-476
Affected
zyxel/atp100 firmware · zyxel/atp100w firmware · zyxel/atp200 firmware · zyxel/atp500 firmware · zyxel/atp700 firmware · zyxel/atp800 firmware · zyxel/usg flex 100 firmware · zyxel/usg flex 100ax firmware · zyxel/usg flex 100h firmware · zyxel/usg flex 100w firmware · zyxel/usg flex 200 firmware · zyxel/usg flex 200h firmware · zyxel/usg flex 200hp firmware · zyxel/usg flex 50 firmware · zyxel/usg flex 500 firmware · zyxel/usg flex 500h firmware · zyxel/usg flex 50w firmware · zyxel/usg flex 700 firmware · zyxel/usg flex 700h firmware
Source
security@zyxel.com.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.