CVE-2023-37929

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE-120)

Published: May 21, 2024 / Updated: 6mo ago

010
CVSS 6.5EPSS 0.04%Medium
CVE info copied to clipboard

The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Timeline

CVE Assignment

NVD published the first details for CVE-2023-37929

May 21, 2024 at 2:15 AM
CVSS

A CVSS base score of 6.5 has been assigned.

May 21, 2024 at 2:20 AM / nvd
First Article

Feedly found the first article mentioning CVE-2023-37929. See article

May 21, 2024 at 2:21 AM / National Vulnerability Database
EPSS

EPSS Score was set to: 0.04% (Percentile: 12.9%)

May 21, 2024 at 9:51 AM
CVSS Estimate

Feedly estimated the CVSS score as HIGH

Jul 16, 2024 at 10:42 PM
Static CVE Timeline Graph

Affected Systems

Zyxel/vmg3625-t50b
+null more

Attack Patterns

CAPEC-10: Buffer Overflow via Environment Variables
+null more

News

CVE-2023-37929
Medium Severity Description The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device. Read more at https://www.tenable.com/cve/CVE-2023-37929
Medium - CVE-2023-37929 - The buffer overflow vulnerability in the CGI...
The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by...
null
- MEDIUM - CVE-2023-37929 The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device.
CVE-2023-37929
The buffer overflow vulnerability in the CGI program of the VMG3625-T50B firmware version V5.50(ABPM.8)C0 could allow an authenticated remote attacker to cause denial of service (DoS) conditions by sending a crafted HTTP request to a vulnerable device. CVE-2023-37929 originally published on CyberSecurityBoard
CVE-2023-37929 | Zyxel VMG3625-T50B 5.50 HTTP Request buffer overflow
A vulnerability, which was classified as critical , was found in Zyxel VMG3625-T50B 5.50 . Affected is an unknown function of the component HTTP Request Handler . The manipulation leads to buffer overflow. This vulnerability is traded as CVE-2023-37929 . It is possible to launch the attack remotely. There is no exploit available.
See 5 more articles and social media posts

CVSS V3.1

Attack Vector:Network
Attack Complexity:Low
Privileges Required:Low
User Interaction:None
Scope:Unchanged
Confidentiality:None
Integrity:None
Availability Impact:High

Categories

Be the first to know about critical vulnerabilities

Collect, analyze, and share vulnerability reports faster using AI