A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1, and USG FLEX H series firmware versions from 1.10 through 1.10 Patch 1 could allow an authenticated IPSec VPN user to cause DoS conditions against the “deviceid” daemon by sending a crafted hostname to an affected device if it has the “Device Insight” feature enabled.
Use CWE-134, Zyxel vendor hub and Atp100 Firmware product page to widen CVE-2023-6399 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-33010, CVE-2023-33009 and CVE-2023-28771 for nearby disclosures in the same product family.