CVE-2023-33009
published 2023-05-24CVE-2023-33009: A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions…
PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-06-26
Exploited in the wild
EPSS
28.14%
97.9th percentile
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | atp100_firmware | — | — |
| zyxel | atp100_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | atp100w_firmware | — | — |
| zyxel | atp100w_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | atp200_firmware | — | — |
| zyxel | atp200_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | atp500_firmware | — | — |
| zyxel | atp500_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | atp700_firmware | — | — |
| zyxel | atp700_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | atp800_firmware | — | — |
| zyxel | atp800_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | atp_series_firmware | — | — |
| zyxel | usg20-vpn_firmware | — | — |
| zyxel | usg20-vpn_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | usg20_vpn_firmware | — | — |
| zyxel | usg_20w-vpn_firmware | — | — |
| zyxel | usg_20w-vpn_firmware | >= 4.60 < 5.36 | 5.36 |
| zyxel | usg_40_firmware | — | — |
| zyxel | usg_40_firmware | >= 4.60 < 4.73 | 4.73 |
| zyxel | usg_40w_firmware | — | — |
| zyxel | usg_40w_firmware | >= 4.60 < 4.73 | 4.73 |
| zyxel | usg_60_firmware | — | — |
| zyxel | usg_60_firmware | >= 4.60 < 4.73 | 4.73 |
| zyxel | usg_60w_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Unauthenticated buffer overflow in the notification function of Zyxel firewall/VPN firmware; target unauthenticated attack surface on affected devices (ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, ZyWALL/USG series) ↗
- →CVE-2023-33009 is listed in CISA KEV, indicating active exploitation in the wild; prioritize detection on Zyxel firewall management/VPN interfaces exposed to unauthenticated traffic ↗
- →CVE-2023-33009 and CVE-2023-33010 are companion buffer overflow vulnerabilities in Zyxel firewall/VPN products; monitor for exploitation attempts targeting both CVEs together ↗
- ·Affected firmware version range for ZyWALL/USG series differs from other product lines — patch threshold is 4.73 Patch 1, not 5.36 Patch 1 ↗
- ·Vendor security advisory is the authoritative source for patch details; CISA references it directly for required remediation actions ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Zyxel Multiple Firewalls Buffer Overflow Vulnerability
cisa·2023-06-05·CVSS 9.8
CVE-2023-33009 [CRITICAL] CWE-120 Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Vulnerability: Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Affected: Zyxel Multiple Firewalls
Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
Required Action: Apply updates per vendor instructions.
Notes: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls; https://nvd.nist.gov/vuln/detail/CVE-2023-33009
Remediation Due Date: 2023-06-26
GHSA
GHSA-g3f9-6h7x-x69v: A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4
ghsa_unreviewed·2023-05-24
CVE-2023-33009 [CRITICAL] CWE-120 GHSA-g3f9-6h7x-x69v: A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
VulnCheck
Zyxel Multiple Firewalls Buffer Overflow Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-33009 [CRITICAL] CWE-120 Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
Affected: Zyxel Multiple Firewalls
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://sektorcert.dk/wp-content/uploads/2023/11/SektorCERT-The-attack-against-Danish-critical-infrastructure-TLP-CLEAR.pdf; https://www.forescout.com/resources/clearing-the-fog-of-war; https://eclypsium.com/blog/infographic-a-history-of-network-device
No detection rules found.
No public exploits indexed.
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewallshttps://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewallshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-33009
2023-05-24
Published
2023-06-05
Added to CISA KEV
Exploited in the wild