4.5

CVE-2024-8882

A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privileges to cause denial of service (DoS) conditions via a crafted URL.

Data is provided by the National Vulnerability Database (NVD)
ZyxelGs1900-8 Firmware Version < 2.90\(aahh.0\)c0
   ZyxelGs1900-8 Version-
ZyxelGs1900-8hp Firmware Version < 2.90\(aahi.0\)c0
   ZyxelGs1900-8hp Version-
ZyxelGs1900-10hp Firmware Version < 2.90\(aazi.0\)c0
   ZyxelGs1900-10hp Version-
ZyxelGs1900-16 Firmware Version < 2.90\(aahj.0\)c0
   ZyxelGs1900-16 Version-
ZyxelGs1900-24 Firmware Version < 2.90\(aahl.0\)c0
   ZyxelGs1900-24 Version-
ZyxelGs1900-24e Firmware Version < 2.90\(aahk.0\)c0
   ZyxelGs1900-24e Version-
ZyxelGs1900-24ep Firmware Version < 2.90\(abto.0\)c0
   ZyxelGs1900-24ep Version-
ZyxelGs1900-24hpv2 Firmware Version < 2.90\(abtp.0\)c0
   ZyxelGs1900-24hpv2 Version-
ZyxelGs1900-48 Firmware Version < 2.90\(aahn.0\)c0
   ZyxelGs1900-48 Version-
ZyxelGs1900-48hpv2 Firmware Version < 2.90\(abtq.0\)c0
   ZyxelGs1900-48hpv2 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.162
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
security@zyxel.com.tw 4.5 0.9 3.6
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.