CVE-2023-33010 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 28.8% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2023-06-26.
Description
A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 28.81% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-120 |
| On CISA KEV | yes — remediate by 2023-06-26 |
| Public exploit | none known |
| Published | 2023-05-24 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Zyxel Multiple Firewalls Buffer Overflow Vulnerability |
|---|---|
| Added | 2023-06-05 |
| Due | 2023-06-26 |
| Vendor / product | Zyxel / Multiple Firewalls |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| zyxel | atp100 |
| zyxel | atp100 firmware |
| zyxel | atp100w |
| zyxel | atp100w firmware |
| zyxel | atp200 |
| zyxel | atp200 firmware |
| zyxel | atp500 |
| zyxel | atp500 firmware |
| zyxel | atp700 |
| zyxel | atp700 firmware |
| zyxel | atp800 |
| zyxel | atp800 firmware |
| zyxel | usg 20w-vpn |
| zyxel | usg 20w-vpn firmware |
| zyxel | usg 40 |
| zyxel | usg 40 firmware |
| zyxel | usg flex 100 |
| zyxel | usg flex 100 firmware |
| zyxel | usg flex 100w |
| zyxel | usg flex 100w firmware |
| zyxel | usg flex 200 |
| zyxel | usg flex 200 firmware |
| zyxel | usg flex 50 |
| zyxel | usg flex 50 firmware |
| zyxel | usg flex 500 |
| zyxel | usg flex 500 firmware |
| zyxel | usg flex 50w |
| zyxel | usg flex 50w firmware |
| zyxel | usg flex 700 |
| zyxel | usg flex 700 firmware |
| zyxel | usg20-vpn |
| zyxel | usg20-vpn firmware |
| zyxel | vpn100 |
| zyxel | vpn100 firmware |
| zyxel | vpn1000 |
| zyxel | vpn1000 firmware |
| zyxel | vpn300 |
| zyxel | vpn300 firmware |
| zyxel | vpn50 |
| zyxel | vpn50 firmware |
References
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls
- https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-33010
→ the Explorer · watch your stack · NVD