6.5

CVE-2023-6397












A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feature enabled.



Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZyxelAtp100 Firmware Version >= 4.32 < 5.37
   ZyxelAtp100 Version-
ZyxelAtp100 Firmware Version5.37 Update-
   ZyxelAtp100 Version-
ZyxelAtp100 Firmware Version5.37 Updatepatch1
   ZyxelAtp100 Version-
ZyxelAtp100w Firmware Version >= 4.32 < 5.37
   ZyxelAtp100w Version-
ZyxelAtp100w Firmware Version5.37 Update-
   ZyxelAtp100w Version-
ZyxelAtp100w Firmware Version5.37 Updatepatch1
   ZyxelAtp100w Version-
ZyxelAtp200 Firmware Version >= 4.32 < 5.37
   ZyxelAtp200 Version-
ZyxelAtp200 Firmware Version5.37 Update-
   ZyxelAtp200 Version-
ZyxelAtp200 Firmware Version5.37 Updatepatch1
   ZyxelAtp200 Version-
ZyxelAtp500 Firmware Version >= 4.32 < 5.37
   ZyxelAtp500 Version-
ZyxelAtp500 Firmware Version5.37 Update-
   ZyxelAtp500 Version-
ZyxelAtp500 Firmware Version5.37 Updatepatch1
   ZyxelAtp500 Version-
ZyxelAtp700 Firmware Version >= 4.32 < 5.37
   ZyxelAtp700 Version-
ZyxelAtp700 Firmware Version5.37 Update-
   ZyxelAtp700 Version-
ZyxelAtp700 Firmware Version5.37 Updatepatch1
   ZyxelAtp700 Version-
ZyxelAtp800 Firmware Version >= 4.32 < 5.37
   ZyxelAtp800 Version-
ZyxelAtp800 Firmware Version5.37 Update-
   ZyxelAtp800 Version-
ZyxelAtp800 Firmware Version5.37 Updatepatch1
   ZyxelAtp800 Version-
ZyxelUsg Flex 100 Firmware Version >= 4.50 < 5.37
   ZyxelUsg Flex 100 Version-
ZyxelUsg Flex 100 Firmware Version5.37 Update-
   ZyxelUsg Flex 100 Version-
ZyxelUsg Flex 100 Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 100 Version-
ZyxelUsg Flex 100ax Firmware Version >= 4.50 < 5.37
   ZyxelUsg Flex 100ax Version-
ZyxelUsg Flex 100ax Firmware Version5.37 Update-
   ZyxelUsg Flex 100ax Version-
ZyxelUsg Flex 100ax Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 100ax Version-
ZyxelUsg Flex 100h Firmware Version >= 4.50 < 5.37
   ZyxelUsg Flex 100h Version-
ZyxelUsg Flex 100h Firmware Version5.37 Update-
   ZyxelUsg Flex 100h Version-
ZyxelUsg Flex 100h Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 100h Version-
ZyxelUsg Flex 100w Firmware Version >= 4.50 < 5.37
   ZyxelUsg Flex 100w Version-
ZyxelUsg Flex 100w Firmware Version5.37 Update-
   ZyxelUsg Flex 100w Version-
ZyxelUsg Flex 100w Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 100w Version-
ZyxelUsg Flex 200 Firmware Version >= 4.50 < 5.37
   ZyxelUsg Flex 200 Version-
ZyxelUsg Flex 200 Firmware Version5.37 Update-
   ZyxelUsg Flex 200 Version-
ZyxelUsg Flex 200 Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 200 Version-
ZyxelUsg Flex 200h Firmware Version >= 4.50 < 5.37
   ZyxelUsg Flex 200h Version-
ZyxelUsg Flex 200h Firmware Version5.37 Update-
   ZyxelUsg Flex 200h Version-
ZyxelUsg Flex 200h Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 200h Version-
ZyxelUsg Flex 200hp Firmware Version >= 4.50 < 5.37
   ZyxelUsg Flex 200hp Version-
ZyxelUsg Flex 200hp Firmware Version5.37 Update-
   ZyxelUsg Flex 200hp Version-
ZyxelUsg Flex 200hp Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 200hp Version-
ZyxelUsg Flex 50 Firmware Version >= 4.50 < 5.37
   ZyxelUsg Flex 50 Version-
ZyxelUsg Flex 50 Firmware Version5.37 Update-
   ZyxelUsg Flex 50 Version-
ZyxelUsg Flex 50 Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 50 Version-
ZyxelUsg Flex 500 Firmware Version >= 4.50 < 5.37
   ZyxelUsg Flex 500 Version-
ZyxelUsg Flex 500 Firmware Version5.37 Update-
   ZyxelUsg Flex 500 Version-
ZyxelUsg Flex 500 Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 500 Version-
ZyxelUsg Flex 500h Firmware Version >= 4.50 < 5.37
   ZyxelUsg Flex 500h Version-
ZyxelUsg Flex 500h Firmware Version5.37 Update-
   ZyxelUsg Flex 500h Version-
ZyxelUsg Flex 500h Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 500h Version-
ZyxelUsg Flex 50w Firmware Version >= 4.50 < 5.37
   ZyxelUsg Flex 50w Version-
ZyxelUsg Flex 50w Firmware Version5.37 Update-
   ZyxelUsg Flex 50w Version-
ZyxelUsg Flex 50w Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 50w Version-
ZyxelUsg Flex 700 Firmware Version >= 4.50 < 5.37
   ZyxelUsg Flex 700 Version-
ZyxelUsg Flex 700 Firmware Version5.37 Update-
   ZyxelUsg Flex 700 Version-
ZyxelUsg Flex 700 Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 700 Version-
ZyxelUsg Flex 700h Firmware Version >= 4.50 < 5.37
   ZyxelUsg Flex 700h Version-
ZyxelUsg Flex 700h Firmware Version5.37 Update-
   ZyxelUsg Flex 700h Version-
ZyxelUsg Flex 700h Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 700h Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.337
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 1.6 3.6
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
security@zyxel.com.tw 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.