Show filters
360 Total Results
Displaying 71-80 of 360
Sort by:
Attacker Value
Unknown
CVE-2023-33095
Disclosure Date: March 04, 2024 (last updated January 12, 2025)
Transient DOS while processing multiple payload container type with incorrect container length received in DL NAS transport OTA in NR.
0
Attacker Value
Unknown
CVE-2023-33086
Disclosure Date: March 04, 2024 (last updated January 12, 2025)
Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.
0
Attacker Value
Unknown
CVE-2023-28578
Disclosure Date: March 04, 2024 (last updated January 12, 2025)
Memory corruption in Core Services while executing the command for removing a single event listener.
0
Attacker Value
Unknown
CVE-2023-6764
Disclosure Date: February 20, 2024 (last updated January 22, 2025)
A format string vulnerability in a function of the IPSec VPN feature in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, and USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1 could allow an attacker to achieve unauthorized remote code execution by sending a sequence of specially crafted payloads containing an invalid pointer; however, such an attack would require detailed knowledge of an affected device’s memory layout and configuration.
0
Attacker Value
Unknown
CVE-2023-6399
Disclosure Date: February 20, 2024 (last updated January 22, 2025)
A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1, and USG FLEX H series firmware versions from 1.10 through 1.10 Patch 1 could allow an authenticated IPSec VPN user to cause DoS conditions against the “deviceid” daemon by sending a crafted hostname to an affected device if it has the “Device Insight” feature enabled.
0
Attacker Value
Unknown
CVE-2023-6398
Disclosure Date: February 20, 2024 (last updated January 22, 2025)
A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1,
USG FLEX H series firmware versions from 1.10 through 1.10 Patch 1,
NWA50AX firmware versions through 6.29(ABYW.3), WAC500 firmware versions through 6.65(ABVS.1), WAX300H firmware versions through 6.60(ACHF.1), and WBE660S firmware versions through 6.65(ACGG.1) could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands on an affected device via FTP.
0
Attacker Value
Unknown
CVE-2023-6397
Disclosure Date: February 20, 2024 (last updated January 22, 2025)
A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feature enabled.
0
Attacker Value
Unknown
CVE-2023-43536
Disclosure Date: February 06, 2024 (last updated February 09, 2024)
Transient DOS while parse fils IE with length equal to 1.
0
Attacker Value
Unknown
CVE-2023-43533
Disclosure Date: February 06, 2024 (last updated February 09, 2024)
Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.
0
Attacker Value
Unknown
CVE-2023-43522
Disclosure Date: February 06, 2024 (last updated February 09, 2024)
Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.
0