6.5

CVE-2023-6399

A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1, and USG FLEX H series firmware versions from 1.10 through 1.10 Patch 1 could allow an authenticated IPSec VPN user to cause DoS conditions against the “deviceid” daemon by sending a crafted hostname to an affected device if it has the “Device Insight” feature enabled.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZyxelAtp100 Firmware Version >= 5.10 < 5.37
   ZyxelAtp100 Version-
ZyxelAtp100 Firmware Version5.37 Update-
   ZyxelAtp100 Version-
ZyxelAtp100 Firmware Version5.37 Updatepatch1
   ZyxelAtp100 Version-
ZyxelAtp100w Firmware Version >= 5.10 < 5.37
   ZyxelAtp100w Version-
ZyxelAtp100w Firmware Version5.37 Update-
   ZyxelAtp100w Version-
ZyxelAtp100w Firmware Version5.37 Updatepatch1
   ZyxelAtp100w Version-
ZyxelAtp200 Firmware Version >= 5.10 < 5.37
   ZyxelAtp200 Version-
ZyxelAtp200 Firmware Version5.37 Update-
   ZyxelAtp200 Version-
ZyxelAtp200 Firmware Version5.37 Updatepatch1
   ZyxelAtp200 Version-
ZyxelAtp500 Firmware Version >= 5.10 < 5.37
   ZyxelAtp500 Version-
ZyxelAtp500 Firmware Version5.37 Update-
   ZyxelAtp500 Version-
ZyxelAtp500 Firmware Version5.37 Updatepatch1
   ZyxelAtp500 Version-
ZyxelAtp700 Firmware Version >= 5.10 < 5.37
   ZyxelAtp700 Version-
ZyxelAtp700 Firmware Version5.37 Update-
   ZyxelAtp700 Version-
ZyxelAtp700 Firmware Version5.37 Updatepatch1
   ZyxelAtp700 Version-
ZyxelAtp800 Firmware Version >= 5.10 < 5.37
   ZyxelAtp800 Version-
ZyxelAtp800 Firmware Version5.37 Update-
   ZyxelAtp800 Version-
ZyxelAtp800 Firmware Version5.37 Updatepatch1
   ZyxelAtp800 Version-
ZyxelUsg Flex 100 Firmware Version >= 5.10 < 5.37
   ZyxelUsg Flex 100 Version-
ZyxelUsg Flex 100 Firmware Version5.37 Update-
   ZyxelUsg Flex 100 Version-
ZyxelUsg Flex 100 Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 100 Version-
ZyxelUsg Flex 100ax Firmware Version >= 5.10 < 5.37
   ZyxelUsg Flex 100ax Version-
ZyxelUsg Flex 100ax Firmware Version5.37 Update-
   ZyxelUsg Flex 100ax Version-
ZyxelUsg Flex 100ax Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 100ax Version-
ZyxelUsg Flex 100h Firmware Version >= 5.10 < 5.37
   ZyxelUsg Flex 100h Version-
ZyxelUsg Flex 100h Firmware Version5.37 Update-
   ZyxelUsg Flex 100h Version-
ZyxelUsg Flex 100h Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 100h Version-
ZyxelUsg Flex 100w Firmware Version >= 5.10 < 5.37
   ZyxelUsg Flex 100w Version-
ZyxelUsg Flex 100w Firmware Version5.37 Update-
   ZyxelUsg Flex 100w Version-
ZyxelUsg Flex 100w Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 100w Version-
ZyxelUsg Flex 200 Firmware Version >= 5.10 < 5.37
   ZyxelUsg Flex 200 Version-
ZyxelUsg Flex 200 Firmware Version5.37 Update-
   ZyxelUsg Flex 200 Version-
ZyxelUsg Flex 200 Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 200 Version-
ZyxelUsg Flex 200h Firmware Version >= 5.10 < 5.37
   ZyxelUsg Flex 200h Version-
ZyxelUsg Flex 200h Firmware Version5.37 Update-
   ZyxelUsg Flex 200h Version-
ZyxelUsg Flex 200h Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 200h Version-
ZyxelUsg Flex 200hp Firmware Version >= 5.10 < 5.37
   ZyxelUsg Flex 200hp Version-
ZyxelUsg Flex 200hp Firmware Version5.37 Update-
   ZyxelUsg Flex 200hp Version-
ZyxelUsg Flex 200hp Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 200hp Version-
ZyxelUsg Flex 500 Firmware Version >= 5.10 < 5.37
   ZyxelUsg Flex 500 Version-
ZyxelUsg Flex 500 Firmware Version5.37 Update-
   ZyxelUsg Flex 500 Version-
ZyxelUsg Flex 500 Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 500 Version-
ZyxelUsg Flex 500h Firmware Version >= 5.10 < 5.37
   ZyxelUsg Flex 500h Version-
ZyxelUsg Flex 500h Firmware Version5.37 Update-
   ZyxelUsg Flex 500h Version-
ZyxelUsg Flex 500h Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 500h Version-
ZyxelUsg Flex 700 Firmware Version >= 5.10 < 5.37
   ZyxelUsg Flex 700 Version-
ZyxelUsg Flex 700 Firmware Version5.37 Update-
   ZyxelUsg Flex 700 Version-
ZyxelUsg Flex 700 Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 700 Version-
ZyxelUsg Flex 700h Firmware Version >= 5.10 < 5.37
   ZyxelUsg Flex 700h Version-
ZyxelUsg Flex 700h Firmware Version5.37 Update-
   ZyxelUsg Flex 700h Version-
ZyxelUsg Flex 700h Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 700h Version-
ZyxelUsg Flex 50 Firmware Version >= 5.10 < 5.37
   ZyxelUsg Flex 50 Version-
ZyxelUsg Flex 50 Firmware Version5.37 Update-
   ZyxelUsg Flex 50 Version-
ZyxelUsg Flex 50 Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 50 Version-
ZyxelUsg Flex 50w Firmware Version >= 5.10 < 5.37
   ZyxelUsg Flex 50w Version-
ZyxelUsg Flex 50w Firmware Version5.37 Update-
   ZyxelUsg Flex 50w Version-
ZyxelUsg Flex 50w Firmware Version5.37 Updatepatch1
   ZyxelUsg Flex 50w Version-
ZyxelUsg20-vpn Firmware Version >= 5.10 < 5.37
   ZyxelUsg20-vpn Version-
ZyxelUsg20-vpn Firmware Version5.37 Update-
   ZyxelUsg20-vpn Version-
ZyxelUsg20-vpn Firmware Version5.37 Updatepatch1
   ZyxelUsg20-vpn Version-
ZyxelUsg20w-vpn Firmware Version >= 5.10 < 5.37
   ZyxelUsg20w-vpn Version-
ZyxelUsg20w-vpn Firmware Version5.37 Update-
   ZyxelUsg20w-vpn Version-
ZyxelUsg20w-vpn Firmware Version5.37 Updatepatch1
   ZyxelUsg20w-vpn Version-
ZyxelUos Version1.10 Update-
   ZyxelUsg Flex 100h Version-
   ZyxelUsg Flex 100hp Version-
   ZyxelUsg Flex 200h Version-
   ZyxelUsg Flex 200hp Version-
   ZyxelUsg Flex 500h Version-
   ZyxelUsg Flex 700h Version-
ZyxelUos Version1.10 Updatepatch1
   ZyxelUsg Flex 100h Version-
   ZyxelUsg Flex 100hp Version-
   ZyxelUsg Flex 200h Version-
   ZyxelUsg Flex 200hp Version-
   ZyxelUsg Flex 500h Version-
   ZyxelUsg Flex 700h Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.531
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
security@zyxel.com.tw 5.7 2.1 3.6
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.