QID 731223
Date Published: 2024-03-01
QID 731223: Zyxel ATP and USG Denial of Service (DoS) Vulnerability
Zyxel ATP and USG devices contains the following security vulnerability:
- CVE-2023-6399: A format string vulnerability could allow an authenticated IPSec VPN user to cause DoS conditions against the deviceid daemon by sending a crafted hostname to an affected device if it has the Device Insight feature enabled.
Zyxel ATP versions ZLD V5.10 to V5.37 Patch 1
Zyxel USG FLEX ZLD V5.10 to V5.37 Patch 1
QID Detection Logic:
This unauthenticated QID detects vulnerable Zyxel versions based on the self reported information exposed via the zld_product_spec.js source file.
NOTE: Since we currently can not detect the patch level of affected devices, this QID is potential.
Successful exploitation could allow a remote attacker to cause a DoS condition on a targeted system.
Solution
Customers are advised to upgrade to ZLD V5.37 Patch 2 or later versions to remediate these vulnerabilities. More information can be found >here.
Vendor References
CVEs related to QID 731223
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Security Advisory |
|