A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device
Published May 24, 2023 ·Due Jun 26, 2023
9.8
CRITICALCVSS 3.1
EPSS 29.02%
Description
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
Affected products
-
Affected
- 4.32 through 5.36 Patch 1
-
Affected
- 4.25 through 5.36 Patch 1
-
Affected
- 4.50 through 5.36 Patch 1
-
Affected
- 4.25 through 5.36 Patch 1
-
Affected
- 4.30 through 5.36 Patch 1
-
Affected
- 4.25 through 4.73 Patch 1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Zyxel | ATP series firmware | unknown | Affected
|
| Zyxel | USG FLEX 50(W) firmware | unknown | Affected
|
| Zyxel | USG FLEX series firmware | unknown | Affected
|
| Zyxel | USG20(W)-VPN firmware | unknown | Affected
|
| Zyxel | VPN series firmware | unknown | Affected
|
| Zyxel | ZyWALL/USG series firmware | unknown | Affected
|
Configuration 1
- ≥ 4.32 · < 5.36
- 5.36
- 5.36
Configuration 2
- ≥ 4.32 · < 5.36
- 5.36
- 5.36
Configuration 3
- ≥ 4.32 · < 5.36
- 5.36
- 5.36
Configuration 4
- ≥ 4.32 · < 5.36
- 5.36
- 5.36
Configuration 5
- ≥ 4.32 · < 5.36
- 5.36
- 5.36
Configuration 6
- ≥ 4.32 · < 5.36
- 5.36
- 5.36
Configuration 7
- ≥ 4.50 · < 5.36
- 5.36
- 5.36
Running on/with
- n/a
Configuration 8
- 5.36
- 5.36
Running on/with
- n/a
Configuration 9
- ≥ 4.50 · < 5.36
- 5.36
- 5.36
Running on/with
- n/a
Configuration 10
- ≥ 4.50 · < 5.36
- 5.36
- 5.36
Running on/with
- n/a
Configuration 11
- ≥ 4.50 · < 5.36
- 5.36
- 5.36
Running on/with
- n/a
Configuration 12
- ≥ 4.50 · < 5.36
- 5.36
- 5.36
Running on/with
- n/a
Configuration 13
- ≥ 4.25 · < 5.36
- 5.36
- 5.36
Running on/with
- n/a
Configuration 14
- 5.36
- 5.36
Running on/with
- n/a
Configuration 15
- ≥ 4.30 · < 5.36
- 5.36
- 5.36
Configuration 16
- ≥ 4.30 · < 5.36
- 5.36
- 5.36
Configuration 17
- ≥ 4.30 · < 5.36
- 5.36
- 5.36
Configuration 18
- ≥ 4.30 · < 5.36
- 5.36
- 5.36
Configuration 19
- ≥ 4.30 · < 5.36
- 5.36
- 5.36
Configuration 20
- ≥ 4.25 · < 4.73
- 4.73
- 4.73
Configuration 21
- ≥ 4.25 · < 4.73
- 4.73
- 4.73
Configuration 22
- ≥ 4.25 · < 4.73
- 4.73
- 4.73
Configuration 23
- ≥ 4.25 · < 4.73
- 4.73
- 4.73
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-37199 Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-33010 government-resourceUS Government Resource
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-37199 | Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-33010 | government-resourceUS Government Resource | |
| https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls | Vendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
ENISA EUVD
GitHub
No data