SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-33009

Zyxel Multiple Firewalls Buffer Overflow Vulnerability

KEVCRITICAL 9.8EPSS 28.1%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 26 June 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
28.14% probability · 98th percentile
CISA KEV
Listed 5 June 2023 · due 26 June 2023
Weakness
CWE-120
Affected
zyxel/atp100 firmware · zyxel/atp200 firmware · zyxel/atp500 firmware · zyxel/atp100w firmware · zyxel/atp700 firmware · zyxel/atp800 firmware · zyxel/usg flex 100 firmware · zyxel/usg flex 50 firmware · zyxel/usg flex 200 firmware · zyxel/usg flex 500 firmware · zyxel/usg flex 700 firmware · zyxel/usg flex 100w firmware · zyxel/usg flex 50w firmware · zyxel/usg 20w-vpn firmware · zyxel/vpn100 firmware · zyxel/vpn50 firmware · zyxel/vpn300 firmware · zyxel/vpn1000 firmware · zyxel/usg20-vpn firmware · zyxel/usg 40 firmware · +3 more
Source
security@zyxel.com.tw

CISA notes

Apply updates per vendor instructions. https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls; https://nvd.nist.gov/vuln/detail/CVE-2023-33009

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.