CVE-2024-0816

MEDIUMCVSS 5.5/10EPSS 0.14%

Last modified

CVE-2024-0816 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.

Description

The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device.

Metrics

CVSS 3.1
5.5/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.14%

4.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ZyxelLte3202-M437 Firmware1.00\(abwf.3\)c0
ZyxelLte3301-Plus Firmware1.00\(abqu.5\)c0
ZyxelLte5388-M804 Firmware1.00\(absq.4\)c0
ZyxelLte5398-M904 Firmware1.00\(abq.4\)c0
ZyxelLte7240-M403 Firmware2.00\(abmg.7\)c0
ZyxelLte7480-M804 Firmware1.00\(abra.8\)c0
ZyxelLte7490-M904 Firmware1.00\(abqy.7\)c0
ZyxelNr5103 Firmware4.19\(abyc.5\)c0
ZyxelNr5103e Firmware1.00\(acdj.1\)b3
ZyxelNr5103ev2 Firmware1.00\(aciq.0\)c0
ZyxelNr5307 Firmware1.00\(acjt.0\)b4
ZyxelNr7101 Firmware1.00\(abu.9\)c0
ZyxelNr7102 Firmware1.00\(abyd.2\)c0
ZyxelNr7103 Firmware1.00\(accz.2\)c0
ZyxelNr7302 Firmware1.00\(acha.2\)c0
ZyxelNr7303 Firmware1.00\(acei.0\)c0
ZyxelNr7501 Firmware1.00\(aceh.0\)c0
ZyxelNebula Fwa505 Firmware1.18\(acko.1\)c0
ZyxelNebula Fwa510 Firmware1.18\(acgd.1\)c0
ZyxelNebula Fwa710 Firmware1.17\(acgc.0\)c0
ZyxelNebula Lte3301-Plus Firmware1.17\(acca.0\)c0
ZyxelNebula Lte7461-M602 Firmware1.15\(ace.3\)c0
ZyxelNebula Nr5101 Firmware1.16\(accg.0\)c0
ZyxelNebula Nr7101 Firmware1.16\(accc.0\)c0
ZyxelDx3300-T1 Firmware5.50\(aby.4\)c0
ZyxelDx3301-T0 Firmware5.50\(aby.4\)c0
ZyxelDx4510 Firmware5.17\(abyl.6\)c0
ZyxelDx5401-B0 Firmware5.17\(abyo.5\)c0
ZyxelDx5401-B1 Firmware5.17\(abyo.5\)c0
ZyxelEmg3525-T50b Firmware5.50\(abpm.8\)c0
ZyxelEmg5523-T50b Firmware5.50\(abpm.8\)c0
ZyxelEmg5723-T50k Firmware5.50\(abom.8.2\)c0
ZyxelEx3300-T1 Firmware5.50\(aby.4\)c0
ZyxelEx3301-T0 Firmware5.50\(aby.4\)c0
ZyxelEx3320-T0 Firmware5.71\(yak.2\)d0
ZyxelEx3320-T1 Firmware5.71\(yap.0\)c0
ZyxelEx3500-T0 Firmware5.44\(achr.0\)c0
ZyxelEx3501-T0 Firmware5.44\(achr.0\)c0
ZyxelEx3510 Firmware5.17\(abup.11\)c0
ZyxelEx5401-B0 Firmware5.17\(abyo.5\)c0
ZyxelEx5401-B1 Firmware5.17\(abyo.5\)c0
ZyxelEx5501-B0 Firmware5.17\(abry.4\)c0
ZyxelEx5510 Firmware5.17\(abqx.9\)c0
ZyxelEx5512-T0 Firmware5.70\(aceg.2\)c0
ZyxelEx5600-T1 Firmware5.70\(acdz.2\)c0
ZyxelEx5601-T0 Firmware5.70\(acdz.2\)c0
ZyxelEx5601-T1 Firmware5.70\(acdz.2\)c0
ZyxelEx7710-B0 Firmware5.18\(acak.0\)c0
ZyxelVmg3625-T50b Firmware5.50\(abpm.8\)c0
ZyxelVmg3927-T50k Firmware5.50\(abom.8.2\)c0

Showing 50 of 65 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-0816?
The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device.
How severe is CVE-2024-0816?
CVE-2024-0816 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 0.14% probability of exploitation in the next 30 days.
How do I fix CVE-2024-0816?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-0816?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST