MEDIUM · 5.9

CVE-2023-25642

There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform ...

Vulnerability Description

There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform a denial of service attack. 

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
ZteMc801A Firmwaremc801a_elisa3_b19
ZteMc801A-
ZteMc801A1 Firmwaremc801a1_elisa1_b04
ZteMc801A1-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-25642?

CVE-2023-25642 is a vulnerability with a CVSS score of 5.9 (MEDIUM). There is a buffer overflow vulnerability in some ZTE mobile internet producsts. Due to insufficient validation of tcp port parameter, an authenticated attacker could use the vulnerability to perform ...

How severe is CVE-2023-25642?

CVE-2023-25642 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-25642?

Check the references section above for vendor advisories and patch information. Affected products include: Zte Mc801A Firmware, Zte Mc801A, Zte Mc801A1 Firmware, Zte Mc801A1.