First published: Mon Aug 13 2007(Updated: )
The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to cause a denial of service (infinite reboot loop) via invalid configuration data. NOTE: this issue might not cross privilege boundaries, and it might be resultant from CSRF; if so, then it should not be included in CVE.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ZyXEL ZyNOS firmware | =3.62 | |
Zyxel Zywall 2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4319 is classified as a moderate severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2007-4319, ensure that only valid configuration data is inputted and restrict access to the management interface.
CVE-2007-4319 affects devices running ZyNOS firmware version 3.62 and the Zyxel Zywall 2.
Yes, CVE-2007-4319 can be exploited remotely by authenticated administrators via invalid configuration data.
The impact of CVE-2007-4319 is a denial of service, resulting in an infinite reboot loop of the affected device.