cbcvebase.
CVE-2023-33010
published 2023-05-24

CVE-2023-33010: A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-06-26
Exploited in the wild
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.

Affected

49 ranges· showing 25
VendorProductVersion rangeFixed in
zyxelatp100_firmware
zyxelatp100_firmware>= 4.32 < 5.365.36
zyxelatp100w_firmware
zyxelatp100w_firmware>= 4.32 < 5.365.36
zyxelatp200_firmware
zyxelatp200_firmware>= 4.32 < 5.365.36
zyxelatp500_firmware
zyxelatp500_firmware>= 4.32 < 5.365.36
zyxelatp700_firmware
zyxelatp700_firmware>= 4.32 < 5.365.36
zyxelatp800_firmware
zyxelatp800_firmware>= 4.32 < 5.365.36
zyxelatp_series_firmware
zyxelusg20-vpn_firmware
zyxelusg20-vpn_firmware>= 4.30 < 5.365.36
zyxelusg20_vpn_firmware
zyxelusg_20w-vpn_firmware
zyxelusg_40_firmware
zyxelusg_40_firmware>= 4.25 < 4.734.73
zyxelusg_40w_firmware
zyxelusg_40w_firmware>= 4.25 < 4.734.73
zyxelusg_60_firmware
zyxelusg_60_firmware>= 4.25 < 4.734.73
zyxelusg_60w_firmware
zyxelusg_60w_firmware>= 4.25 < 4.734.73

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL