CVE-2022-43393

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/01/2023
Last modified:
18/01/2023

Description

An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0, which could allow an unauthenticated attacker to corrupt the contents of the memory and result in a denial-of-service (DoS) condition on a vulnerable device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:zyxel:gs1350-6hp_firmware:*:*:*:*:*:*:*:* 4.70\(abpi.5\)c0 (excluding)
cpe:2.3:h:zyxel:gs1350-6hp:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:gs1350-12hp_firmware:*:*:*:*:*:*:*:* 4.70\(abpj.5\)c0 (excluding)
cpe:2.3:h:zyxel:gs1350-12hp:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:gs1350-18hp_firmware:*:*:*:*:*:*:*:* 4.70\(abpk.5\)c0 (excluding)
cpe:2.3:h:zyxel:gs1350-18hp:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:gs1350-26hp_firmware:*:*:*:*:*:*:*:* 4.70\(abpl.5\)c0 (excluding)
cpe:2.3:h:zyxel:gs1350-26hp:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:gs1915-8_firmware:*:*:*:*:*:*:*:* 4.70\(acap.3\)c0 (excluding)
cpe:2.3:h:zyxel:gs1915-8:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:gs1915-8ep_firmware:*:*:*:*:*:*:*:* 4.70\(acaq.3\)c0 (excluding)
cpe:2.3:h:zyxel:gs1915-8ep:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:gs1915-24e_firmware:*:*:*:*:*:*:*:* 4.70\(acdr.3\)c0 (excluding)
cpe:2.3:h:zyxel:gs1915-24e:-:*:*:*:*:*:*:*
cpe:2.3:o:zyxel:gs1915-24ep_firmware:*:*:*:*:*:*:*:* 4.70\(acds.3\)c0 (excluding)