CVE-2023-33010
published 2023-05-24CVE-2023-33010: A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware…
PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-06-26
Exploited in the wild
EPSS
28.81%
97.9th percentile
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| zyxel | atp100_firmware | — | — |
| zyxel | atp100_firmware | >= 4.32 < 5.36 | 5.36 |
| zyxel | atp100w_firmware | — | — |
| zyxel | atp100w_firmware | >= 4.32 < 5.36 | 5.36 |
| zyxel | atp200_firmware | — | — |
| zyxel | atp200_firmware | >= 4.32 < 5.36 | 5.36 |
| zyxel | atp500_firmware | — | — |
| zyxel | atp500_firmware | >= 4.32 < 5.36 | 5.36 |
| zyxel | atp700_firmware | — | — |
| zyxel | atp700_firmware | >= 4.32 < 5.36 | 5.36 |
| zyxel | atp800_firmware | — | — |
| zyxel | atp800_firmware | >= 4.32 < 5.36 | 5.36 |
| zyxel | atp_series_firmware | — | — |
| zyxel | usg20-vpn_firmware | — | — |
| zyxel | usg20-vpn_firmware | >= 4.30 < 5.36 | 5.36 |
| zyxel | usg20_vpn_firmware | — | — |
| zyxel | usg_20w-vpn_firmware | — | — |
| zyxel | usg_40_firmware | — | — |
| zyxel | usg_40_firmware | >= 4.25 < 4.73 | 4.73 |
| zyxel | usg_40w_firmware | — | — |
| zyxel | usg_40w_firmware | >= 4.25 < 4.73 | 4.73 |
| zyxel | usg_60_firmware | — | — |
| zyxel | usg_60_firmware | >= 4.25 < 4.73 | 4.73 |
| zyxel | usg_60w_firmware | — | — |
| zyxel | usg_60w_firmware | >= 4.25 < 4.73 | 4.73 |
Detection & IOCsextracted from sources · hover to see the quote
- →Unauthenticated buffer overflow in the ID processing function of Zyxel firewall/VPN firmware; target attack surface is pre-auth, so look for anomalous/oversized IKE or VPN ID payloads sent to affected devices ↗
- →Exploitation requires no authentication; monitor for unexpected crashes, reboots, or unresponsive states on Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewall devices as potential DoS indicators ↗
- →CVE-2023-33010 is grouped with CVE-2023-33009 as a pair of buffer overflow vulnerabilities in Zyxel firewall/VPN products; detections should cover both CVEs on the same affected device population ↗
- ·Affected firmware ranges are broad; ensure version checks cover all listed product lines before concluding a device is patched ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fqv9-84fh-jjgr: A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4
ghsa_unreviewed·2023-05-24
CVE-2023-33010 [CRITICAL] CWE-120 GHSA-fqv9-84fh-jjgr: A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
VulnCheck
Zyxel Multiple Firewalls Buffer Overflow Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-33010 [CRITICAL] CWE-120 Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
Affected: Zyxel Multiple Firewalls
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://sektorcert.dk/wp-content/uploads/2023/11/SektorCERT-The-attack-against-Danish-critical-infrastructure-TLP-CLEAR.pdf; https://www.forescout.com/resources/clearing-the-fog-of-war; https://www.cisa.gov/sites/default/files/2024-07/aa24-207a-dprk-c
CISA
Zyxel Multiple Firewalls Buffer Overflow Vulnerability
cisa·2023-06-05·CVSS 9.8
CVE-2023-33010 [CRITICAL] CWE-120 Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Vulnerability: Zyxel Multiple Firewalls Buffer Overflow Vulnerability
Affected: Zyxel Multiple Firewalls
Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the ID processing function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
Required Action: Apply updates per vendor instructions.
Notes: https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls; https://nvd.nist.gov/vuln/detail/CVE-2023-33010
Remediation Due Date: 2023-06-26
No detection rules found.
No public exploits indexed.
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewallshttps://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewallshttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-33010
2023-05-24
Published
2023-06-05
Added to CISA KEV
Exploited in the wild