CVE-2023-6397: Null Pointer Dereference
A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 through 5.37 Patch 1 could allow a LAN-based attacker to cause denial-of-service (DoS) conditions by downloading a crafted RAR compressed file onto a LAN-side host if the firewall has the “Anti-Malware” feature enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6397?
CVE-2023-6397 is classified as a denial-of-service vulnerability.
How do I fix CVE-2023-6397?
To fix CVE-2023-6397, update Zyxel ATP and USG FLEX series firmware to versions 5.37 Patch 2 or later.
Which Zyxel firmware versions are affected by CVE-2023-6397?
CVE-2023-6397 affects Zyxel ATP series firmware versions 4.32 to 5.37 Patch 1 and USG FLEX series firmware versions 4.50 to 5.37 Patch 1.
Can CVE-2023-6397 be exploited remotely?
CVE-2023-6397 requires a LAN-based attacker to exploit the vulnerability.
What type of attack can CVE-2023-6397 facilitate?
CVE-2023-6397 can cause denial-of-service (DoS) conditions on affected devices.