CVE-2023-33009
Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 26 June 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 28.14% probability · 98th percentile
- CISA KEV
- Listed 5 June 2023 · due 26 June 2023
- Weakness
- CWE-120
- Affected
- zyxel/atp100 firmware · zyxel/atp200 firmware · zyxel/atp500 firmware · zyxel/atp100w firmware · zyxel/atp700 firmware · zyxel/atp800 firmware · zyxel/usg flex 100 firmware · zyxel/usg flex 50 firmware · zyxel/usg flex 200 firmware · zyxel/usg flex 500 firmware · zyxel/usg flex 700 firmware · zyxel/usg flex 100w firmware · zyxel/usg flex 50w firmware · zyxel/usg 20w-vpn firmware · zyxel/vpn100 firmware · zyxel/vpn50 firmware · zyxel/vpn300 firmware · zyxel/vpn1000 firmware · zyxel/usg20-vpn firmware · zyxel/usg 40 firmware · +3 more
- Source
- security@zyxel.com.tw
CISA notes
Apply updates per vendor instructions. https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls; https://nvd.nist.gov/vuln/detail/CVE-2023-33009
References
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewallsVendor Advisory
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewallsVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-33009US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.