A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1, and USG FLEX H series firmware versions from 1.10 through 1.10 Patch 1 could allow an authenticated IPSec VPN user to cause DoS conditions against the “deviceid” daemon by sending a crafted hostname to an affected device if it has the “Device Insight” feature enabled.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Zyxel
Published: 2024-02-20T01:42:21.027Z
Updated: 2024-08-02T08:28:21.797Z
Reserved: 2023-11-30T07:58:19.503Z
Link: CVE-2023-6399
Vulnrichment
Updated: 2024-08-02T08:28:21.797Z
NVD
Status : Awaiting Analysis
Published: 2024-02-20T02:15:49.407
Modified: 2024-11-21T08:43:46.957
Link: CVE-2023-6399
Redhat
No data.