9.8

CVE-2023-33009

Warning

A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.

Data is provided by the National Vulnerability Database (NVD)
ZyxelAtp100 Firmware Version >= 4.60 < 5.36
   ZyxelAtp100 Version-
ZyxelAtp100 Firmware Version5.36 Update-
   ZyxelAtp100 Version-
ZyxelAtp100 Firmware Version5.36 Updatepatch1
   ZyxelAtp100 Version-
ZyxelAtp200 Firmware Version >= 4.60 < 5.36
   ZyxelAtp200 Version-
ZyxelAtp200 Firmware Version5.36 Update-
   ZyxelAtp200 Version-
ZyxelAtp200 Firmware Version5.36 Updatepatch1
   ZyxelAtp200 Version-
ZyxelAtp500 Firmware Version >= 4.60 < 5.36
   ZyxelAtp500 Version-
ZyxelAtp500 Firmware Version5.36 Update-
   ZyxelAtp500 Version-
ZyxelAtp500 Firmware Version5.36 Updatepatch1
   ZyxelAtp500 Version-
ZyxelAtp100w Firmware Version >= 4.60 < 5.36
   ZyxelAtp100w Version-
ZyxelAtp100w Firmware Version5.36 Update-
   ZyxelAtp100w Version-
ZyxelAtp100w Firmware Version5.36 Updatepatch1
   ZyxelAtp100w Version-
ZyxelAtp700 Firmware Version >= 4.60 < 5.36
   ZyxelAtp700 Version-
ZyxelAtp700 Firmware Version5.36 Update-
   ZyxelAtp700 Version-
ZyxelAtp700 Firmware Version5.36 Updatepatch1
   ZyxelAtp700 Version-
ZyxelAtp800 Firmware Version >= 4.60 < 5.36
   ZyxelAtp800 Version-
ZyxelAtp800 Firmware Version5.36 Update-
   ZyxelAtp800 Version-
ZyxelAtp800 Firmware Version5.36 Updatepatch1
   ZyxelAtp800 Version-
ZyxelUsg Flex 100 Firmware Version >= 4.60 < 5.36
   ZyxelUsg Flex 100 Version-
ZyxelUsg Flex 100 Firmware Version5.36 Update-
   ZyxelUsg Flex 100 Version-
ZyxelUsg Flex 100 Firmware Version5.36 Updatepatch1
   ZyxelUsg Flex 100 Version-
ZyxelUsg Flex 50 Firmware Version >= 4.60 < 5.36
   ZyxelUsg Flex 50 Version-
ZyxelUsg Flex 50 Firmware Version5.36 Update-
   ZyxelUsg Flex 50 Version-
ZyxelUsg Flex 50 Firmware Version5.36 Updatepatch1
   ZyxelUsg Flex 50 Version-
ZyxelUsg Flex 200 Firmware Version >= 4.60 < 5.36
   ZyxelUsg Flex 200 Version-
ZyxelUsg Flex 200 Firmware Version5.36 Update-
   ZyxelUsg Flex 200 Version-
ZyxelUsg Flex 200 Firmware Version5.36 Updatepatch1
   ZyxelUsg Flex 200 Version-
ZyxelUsg Flex 500 Firmware Version >= 4.60 < 5.36
   ZyxelUsg Flex 500 Version-
ZyxelUsg Flex 500 Firmware Version5.36 Update-
   ZyxelUsg Flex 500 Version-
ZyxelUsg Flex 500 Firmware Version5.36 Updatepatch1
   ZyxelUsg Flex 500 Version-
ZyxelUsg Flex 700 Firmware Version >= 4.60 < 5.36
   ZyxelUsg Flex 700 Version-
ZyxelUsg Flex 700 Firmware Version5.36 Update-
   ZyxelUsg Flex 700 Version-
ZyxelUsg Flex 700 Firmware Version5.36 Updatepatch1
   ZyxelUsg Flex 700 Version-
ZyxelUsg Flex 100 Firmware Version >= 4.60 < 5.36
   ZyxelUsg Flex 100w Version-
ZyxelUsg Flex 100w Firmware Version5.36 Update-
   ZyxelUsg Flex 100w Version-
ZyxelUsg Flex 100w Firmware Version5.36 Updatepatch1
   ZyxelUsg Flex 100w Version-
ZyxelUsg Flex 50w Firmware Version >= 4.60 < 5.36
   ZyxelUsg Flex 50w Version-
ZyxelUsg Flex 50w Firmware Version5.36 Update-
   ZyxelUsg Flex 50w Version-
ZyxelUsg Flex 50w Firmware Version5.36 Updatepatch1
   ZyxelUsg Flex 50w Version-
ZyxelUsg 20w-vpn Firmware Version >= 4.60 < 5.36
   ZyxelUsg 20w-vpn Version-
ZyxelUsg 20w-vpn Firmware Version5.36 Update-
   ZyxelUsg 20w-vpn Version-
ZyxelUsg 20w-vpn Firmware Version5.36 Updatepatch1
   ZyxelUsg 20w-vpn Version-
ZyxelVpn100 Firmware Version >= 4.60 < 5.36
   ZyxelVpn100 Version-
ZyxelVpn100 Firmware Version5.36 Update-
   ZyxelVpn100 Version-
ZyxelVpn100 Firmware Version5.36 Updatepatch1
   ZyxelVpn100 Version-
ZyxelVpn50 Firmware Version >= 4.60 < 5.36
   ZyxelVpn50 Version-
ZyxelVpn50 Firmware Version5.36 Update-
   ZyxelVpn50 Version-
ZyxelVpn50 Firmware Version5.36 Updatepatch1
   ZyxelVpn50 Version-
ZyxelVpn300 Firmware Version >= 4.60 < 5.36
   ZyxelVpn300 Version-
ZyxelVpn300 Firmware Version5.36 Update-
   ZyxelVpn300 Version-
ZyxelVpn300 Firmware Version5.36 Updatepatch1
   ZyxelVpn300 Version-
ZyxelVpn1000 Firmware Version >= 4.60 < 5.36
   ZyxelVpn1000 Version-
ZyxelVpn1000 Firmware Version5.36 Update-
   ZyxelVpn1000 Version-
ZyxelVpn1000 Firmware Version5.36 Updatepatch1
   ZyxelVpn1000 Version-
ZyxelUsg20-vpn Firmware Version >= 4.60 < 5.36
   ZyxelUsg20-vpn Version-
ZyxelUsg20-vpn Firmware Version5.36 Update-
   ZyxelUsg20-vpn Version-
ZyxelUsg20-vpn Firmware Version5.36 Updatepatch1
   ZyxelUsg20-vpn Version-
ZyxelUsg 40 Firmware Version >= 4.60 < 4.73
   ZyxelUsg 40 Version-
ZyxelUsg 40 Firmware Version4.73 Update-
   ZyxelUsg 40 Version-
ZyxelUsg 40 Firmware Version4.73 Updatepatch1
   ZyxelUsg 40 Version-
ZyxelUsg 40w Firmware Version >= 4.60 < 4.73
   ZyxelUsg 40w Version-
ZyxelUsg 40w Firmware Version4.73 Update-
   ZyxelUsg 40w Version-
ZyxelUsg 40w Firmware Version4.73 Updatepatch1
   ZyxelUsg 40w Version-
ZyxelUsg 60w Firmware Version >= 4.60 < 4.73
   ZyxelUsg 60w Version-
ZyxelUsg 60w Firmware Version4.73 Update-
   ZyxelUsg 60w Version-
ZyxelUsg 60w Firmware Version4.73 Updatepatch1
   ZyxelUsg 60w Version-
ZyxelUsg 60 Firmware Version >= 4.60 < 4.73
   ZyxelUsg 60 Version-
ZyxelUsg 60 Firmware Version4.73 Update-
   ZyxelUsg 60 Version-
ZyxelUsg 60 Firmware Version4.73 Updatepatch1
   ZyxelUsg 60 Version-

05.06.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Zyxel Multiple Firewalls Buffer Overflow Vulnerability

Vulnerability

Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.64% 0.887
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
security@zyxel.com.tw 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.