Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wj52-rfj4-xjcm

Опубликовано: 20 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feature enabled.

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feature enabled.

EPSS

Процентиль: 33%
0.00129
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 6.5
nvd
почти 2 года назад

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feature enabled.

CVSS3: 6.5
fstec
около 2 лет назад

Уязвимость функции Anti-Malware микропрограммного обеспечения сетевых устройств ZyXEL USG FLEX и ATP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 33%
0.00129
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-476