First published: Thu Dec 14 2023(Updated: )
There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack.
Credit: psirt@zte.com.cn
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ZTE MC801A Firmware | =mc801a_elisa3_b19 | |
ZTE MC801A1 | ||
All of | ||
ZTE MC801A1 Firmware | =mc801a1_elisa1_b04 | |
ZTE MC801A1 Firmware |
MC801A_Elisa3_B22, MC801A1_Elisa1_B06
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25642 is considered a high-severity vulnerability due to its potential to allow denial of service attacks.
To mitigate CVE-2023-25642, ensure that you update the affected ZTE mobile internet products to the latest firmware version provided by ZTE.
CVE-2023-25642 affects specific firmware versions of the ZTE MC801A and MC801A1 products.
CVE-2023-25642 can be exploited by an authenticated attacker to perform a denial of service attack.
CVE-2023-25642 is caused by insufficient validation of the TCP port parameter in certain ZTE mobile internet products.