peter bassill · operator
$ cve CVE-2023-33009 JSON

CVE-2023-33009 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 28.1% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2023-06-26.

Description

A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS28.14% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-120
On CISA KEVyes — remediate by 2023-06-26
Public exploitnone known
Published2023-05-24
Last modified2026-06-17

CISA KEV

NameZyxel Multiple Firewalls Buffer Overflow Vulnerability
Added2023-06-05
Due2023-06-26
Vendor / productZyxel / Multiple Firewalls
Ransomware usenone reported

Affected (40)

VendorProduct
zyxelatp100
zyxelatp100 firmware
zyxelatp100w
zyxelatp100w firmware
zyxelatp200
zyxelatp200 firmware
zyxelatp500
zyxelatp500 firmware
zyxelatp700
zyxelatp700 firmware
zyxelatp800
zyxelatp800 firmware
zyxelusg 20w-vpn
zyxelusg 20w-vpn firmware
zyxelusg 40
zyxelusg 40 firmware
zyxelusg flex 100
zyxelusg flex 100 firmware
zyxelusg flex 100w
zyxelusg flex 100w firmware
zyxelusg flex 200
zyxelusg flex 200 firmware
zyxelusg flex 50
zyxelusg flex 50 firmware
zyxelusg flex 500
zyxelusg flex 500 firmware
zyxelusg flex 50w
zyxelusg flex 50w firmware
zyxelusg flex 700
zyxelusg flex 700 firmware
zyxelusg20-vpn
zyxelusg20-vpn firmware
zyxelvpn100
zyxelvpn100 firmware
zyxelvpn1000
zyxelvpn1000 firmware
zyxelvpn300
zyxelvpn300 firmware
zyxelvpn50
zyxelvpn50 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD