⚠ Actively exploited
Added to CISA KEV on 2023-06-05. Federal agencies required to patch by 2023-06-26. Required action: Apply updates per vendor instructions..

CVE-2023-33010

Severity
9.8CRITICAL
EPSS
5.9%
top 9.45%
CISA KEV
KEV
Added 2023-06-05
Due 2023-06-26
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedMay 24
KEV addedJun 5
KEV dueJun 26
CISA Required Action: Apply updates per vendor instructions.

Description

A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) co

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages29 packages

CVEListV5zyxel/usg_flex_series_firmware4.50 through 5.36 Patch 1
CVEListV5zyxel/zywall/usg_series_firmware4.25 through 4.73 Patch 1
CVEListV5zyxel/atp_series_firmware4.32 through 5.36 Patch 1
CVEListV5zyxel/vpn_series_firmware4.30 through 5.36 Patch 1
NVDzyxel/usg_flex_100_firmware4.505.36+1

🔴Vulnerability Details

3
GHSA
GHSA-fqv9-84fh-jjgr: A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 42023-05-24
CVEList
CVE-2023-33010: A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 42023-05-24
VulnCheck
Zyxel Multiple Firewalls Buffer Overflow Vulnerability2023

📋Vendor Advisories

1
CISA
Zyxel Multiple Firewalls Buffer Overflow Vulnerability2023-06-05
CVE-2023-33010 (CRITICAL CVSS 9.8) | A buffer overflow vulnerability in | cvebase.io