SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-0816

The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device.

MEDIUM 5.5EPSS 0.14%

Does this matter?

Lower severity and a low EPSS score (0.14%). Track it; it rarely justifies an emergency change on its own.

Description

The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.14% probability · 4th percentile
CISA KEV
Not listed
Weakness
CWE-120
Affected
zyxel/lte3202-m437 firmware · zyxel/lte3301-plus firmware · zyxel/lte5388-m804 firmware · zyxel/lte5398-m904 firmware · zyxel/lte7240-m403 firmware · zyxel/lte7480-m804 firmware · zyxel/lte7490-m904 firmware · zyxel/nr5103 firmware · zyxel/nr5103e firmware · zyxel/nr5103ev2 firmware · zyxel/nr5307 firmware · zyxel/nr7101 firmware · zyxel/nr7102 firmware · zyxel/nr7103 firmware · zyxel/nr7302 firmware · zyxel/nr7303 firmware · zyxel/nr7501 firmware · zyxel/nebula fwa505 firmware · zyxel/nebula fwa510 firmware · zyxel/nebula fwa710 firmware · +40 more
Source
security@zyxel.com.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.