cbcvebase.
CVE-2023-33010
published 2023-05-24

CVE-2023-33010: A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware…

PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-06-26
Exploited in the wild
EPSS
28.81%
97.9th percentile
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.

Affected

49 ranges· showing 25
VendorProductVersion rangeFixed in
zyxelatp100_firmware
zyxelatp100_firmware>= 4.32 < 5.365.36
zyxelatp100w_firmware
zyxelatp100w_firmware>= 4.32 < 5.365.36
zyxelatp200_firmware
zyxelatp200_firmware>= 4.32 < 5.365.36
zyxelatp500_firmware
zyxelatp500_firmware>= 4.32 < 5.365.36
zyxelatp700_firmware
zyxelatp700_firmware>= 4.32 < 5.365.36
zyxelatp800_firmware
zyxelatp800_firmware>= 4.32 < 5.365.36
zyxelatp_series_firmware
zyxelusg20-vpn_firmware
zyxelusg20-vpn_firmware>= 4.30 < 5.365.36
zyxelusg20_vpn_firmware
zyxelusg_20w-vpn_firmware
zyxelusg_40_firmware
zyxelusg_40_firmware>= 4.25 < 4.734.73
zyxelusg_40w_firmware
zyxelusg_40w_firmware>= 4.25 < 4.734.73
zyxelusg_60_firmware
zyxelusg_60_firmware>= 4.25 < 4.734.73
zyxelusg_60w_firmware
zyxelusg_60w_firmware>= 4.25 < 4.734.73

Detection & IOCsextracted from sources · hover to see the quote

  • Unauthenticated buffer overflow in the ID processing function of Zyxel firewall/VPN firmware; target attack surface is pre-auth, so look for anomalous/oversized IKE or VPN ID payloads sent to affected devices
  • Exploitation requires no authentication; monitor for unexpected crashes, reboots, or unresponsive states on Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewall devices as potential DoS indicators
  • CVE-2023-33010 is grouped with CVE-2023-33009 as a pair of buffer overflow vulnerabilities in Zyxel firewall/VPN products; detections should cover both CVEs on the same affected device population
  • ·Affected firmware ranges are broad; ensure version checks cover all listed product lines before concluding a device is patched

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.