CVE-2024-9197: Buffer Overflow
A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker with administrator privileges to cause a temporary denial of service (DoS) condition against the web management interface by sending a crafted HTTP GET request to a vulnerable device if the function ZyEE is enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9197?
CVE-2024-9197 is categorized as a high severity vulnerability due to the potential for temporary denial of service by authenticated attackers.
How do I fix CVE-2024-9197?
To mitigate CVE-2024-9197, upgrade the firmware of affected Zyxel devices to the latest version beyond V5.50(ABPM.9.3)C0.
What devices are affected by CVE-2024-9197?
CVE-2024-9197 affects Zyxel VMG3625-T50B and several other Zyxel firmware models up to specific versions indicated in the advisory.
How does CVE-2024-9197 affect my device?
CVE-2024-9197 allows authenticated attackers with administrator privileges to exploit a buffer overflow condition, potentially causing a denial of service.
Can CVE-2024-9197 be exploited remotely?
CVE-2024-9197 requires authentication, meaning an attacker must already have administrator access to exploit the vulnerability.