← All CVEs

CVE-2023-33010

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2023-06-05Remediation due 2023-06-26

A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.

9.8
CVSS
28.8%
EPSS (exploit prob.)
98th
EPSS percentile
2023-05-24
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-120

Affected products

VendorProductAffected versions
zyxelatp100_firmware>= 4.32, < 5.36
zyxelatp100_firmware5.36
zyxelatp100_firmware5.36
zyxelatp100all versions
zyxelatp200_firmware>= 4.32, < 5.36
zyxelatp200_firmware5.36
zyxelatp200_firmware5.36
zyxelatp200all versions
zyxelatp500_firmware>= 4.32, < 5.36
zyxelatp500_firmware5.36
zyxelatp500_firmware5.36
zyxelatp500all versions
zyxelatp100w_firmware>= 4.32, < 5.36
zyxelatp100w_firmware5.36
zyxelatp100w_firmware5.36
zyxelatp100wall versions
zyxelatp700_firmware>= 4.32, < 5.36
zyxelatp700_firmware5.36
zyxelatp700_firmware5.36
zyxelatp700all versions
zyxelatp800_firmware>= 4.32, < 5.36
zyxelatp800_firmware5.36
zyxelatp800_firmware5.36
zyxelatp800all versions
zyxelusg_flex_100_firmware>= 4.50, < 5.36
zyxelusg_flex_100_firmware5.36
zyxelusg_flex_100_firmware5.36
zyxelusg_flex_100all versions
zyxelusg_flex_50_firmware5.36
zyxelusg_flex_50_firmware5.36
zyxelusg_flex_50all versions
zyxelusg_flex_200_firmware>= 4.50, < 5.36
zyxelusg_flex_200_firmware5.36
zyxelusg_flex_200_firmware5.36
zyxelusg_flex_200all versions
zyxelusg_flex_500_firmware>= 4.50, < 5.36
zyxelusg_flex_500_firmware5.36
zyxelusg_flex_500_firmware5.36
zyxelusg_flex_500all versions
zyxelusg_flex_700_firmware>= 4.50, < 5.36

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-33010