Vulnerability Description
The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zyxel | Dx3300-T1 Firmware | 5.50\(aby.4\)c0 |
| Zyxel | Dx3300-T1 | - |
| Zyxel | Dx3301-T0 Firmware | 5.50\(aby.4\)c0 |
| Zyxel | Dx3301-T0 | - |
| Zyxel | Dx4510 Firmware | 5.17\(abyl.5\)c0 |
| Zyxel | Dx4510 | - |
| Zyxel | Dx5401-B0 Firmware | 5.17\(abyo.5\)c0 |
| Zyxel | Dx5401-B0 | - |
| Zyxel | Dx5401-B1 Firmware | 5.17\(abyo.5\)c0 |
| Zyxel | Dx5401-B1 | - |
| Zyxel | Emg3525-T50B Firmware | 5.50\(abpm.8\)c0 |
| Zyxel | Emg3525-T50B | - |
| Zyxel | Emg5523-T50B Firmware | 5.50\(abpm.8\)c0 |
| Zyxel | Emg5523-T50B | - |
| Zyxel | Emg5723-T50K Firmware | 5.50\(abom.8.2\)c0 |
| Zyxel | Emg5723-T50K | - |
| Zyxel | Ex3300-T1 Firmware | 5.50\(aby.4\)c0 |
| Zyxel | Ex3300-T1 | - |
| Zyxel | Ex3301-T0 Firmware | 5.50\(aby.4\)c0 |
| Zyxel | Ex3301-T0 | - |
Related Weaknesses (CWE)
References
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisVendor Advisory
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisVendor Advisory
FAQ
What is CVE-2023-37929?
CVE-2023-37929 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by se...
How severe is CVE-2023-37929?
CVE-2023-37929 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-37929?
Check the references section above for vendor advisories and patch information. Affected products include: Zyxel Dx3300-T1 Firmware, Zyxel Dx3300-T1, Zyxel Dx3301-T0 Firmware, Zyxel Dx3301-T0, Zyxel Dx4510 Firmware.