CVE-2024-0816

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') (CWE-120)

Published: May 21, 2024 / Updated: 6mo ago

010
CVSS 5.5EPSS 0.04%Medium
CVE info copied to clipboard

The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Timeline

CVE Assignment

NVD published the first details for CVE-2024-0816

May 21, 2024 at 2:15 AM
CVSS

A CVSS base score of 5.5 has been assigned.

May 21, 2024 at 2:20 AM / nvd
First Article

Feedly found the first article mentioning CVE-2024-0816. See article

May 21, 2024 at 2:21 AM / National Vulnerability Database
EPSS

EPSS Score was set to: 0.04% (Percentile: 8.6%)

May 21, 2024 at 9:51 AM
CVSS Estimate

Feedly estimated the CVSS score as MEDIUM

Jul 16, 2024 at 10:42 PM
Static CVE Timeline Graph

Affected Systems

Zyxel/dx3300-t1
+null more

Attack Patterns

CAPEC-10: Buffer Overflow via Environment Variables
+null more

News

CVE-2024-0816
Medium Severity Description The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device. Read more at https://www.tenable.com/cve/CVE-2024-0816
Medium - CVE-2024-0816 - The buffer overflow vulnerability in the...
The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI...
CVE-2024-0816
The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device. CVE-2024-0816 originally published on CyberSecurityBoard
CVE-2024-0816 | Zyxel DX3300-T1 V5.50(ABVY.4)C0 CLI buffer overflow
A vulnerability was found in Zyxel DX3300-T1 V5.50(ABVY.4)C0 . It has been rated as critical . This issue affects some unknown processing of the component CLI . The manipulation leads to buffer overflow. The identification of this vulnerability is CVE-2024-0816 . It is possible to launch the attack on the local host. There is no exploit available.
null
Zyxel - MEDIUM - CVE-2024-0816 The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local attacker to cause denial of service (DoS) conditions by executing the CLI command with crafted strings on an affected device.
See 6 more articles and social media posts

CVSS V3.1

Attack Vector:Local
Attack Complexity:Low
Privileges Required:Low
User Interaction:None
Scope:Unchanged
Confidentiality:None
Integrity:None
Availability Impact:High

Categories

Be the first to know about critical vulnerabilities

Collect, analyze, and share vulnerability reports faster using AI