Vulnerability Description
There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zte | Mc801A Firmware | mc801a_elisa3_b19 |
| Zte | Mc801A | - |
| Zte | Mc801A1 Firmware | mc801a1_elisa1_b04 |
| Zte | Mc801A1 | - |
Related Weaknesses (CWE)
References
- https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1032504Vendor Advisory
- https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1032504Vendor Advisory
FAQ
What is CVE-2023-25642?
CVE-2023-25642 is a vulnerability with a CVSS score of 5.9 (MEDIUM). There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform ...
How severe is CVE-2023-25642?
CVE-2023-25642 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25642?
Check the references section above for vendor advisories and patch information. Affected products include: Zte Mc801A Firmware, Zte Mc801A, Zte Mc801A1 Firmware, Zte Mc801A1.