ZeroHour

CVE-2023-33009

KEVlarge

Unauthenticated Buffer Overflow in Zyxel ATP, USG FLEX and ZyWALL/USG Firewalls

CISA: Zyxel Multiple Firewalls Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
28%p98
Published
()
KEV added
AI analysis

CVE-2023-33009 is an unauthenticated buffer overflow (CWE-120) in the notification function of Zyxel firewall firmware. A remote attacker who can reach the affected device can send crafted input to the notification function without any credentials, overflowing a buffer. Successful exploitation can crash the device (denial of service) and enable remote code execution on the appliance. Affected products are Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG series firewalls, which are commonly deployed as perimeter and VPN gateways in small and mid-size networks. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2023-06-05, indicating observed exploitation in the wild; no public proof-of-concept is known, and EPSS assigns a 28.1% probability of exploitation within 30 days (98th percentile).

What to do: Apply the fixed firmware for CVE-2023-33009 from Zyxel's security advisory, per the CISA KEV required action (specific fixed versions are not listed in the source data). Until patched, restrict internet exposure of device management, notification, and VPN interfaces and watch for unexpected crashes or reboots on affected ATP, USG FLEX, VPN, or ZyWALL/USG appliances.

Affected
Zyxel ATP series firewalls
Zyxel USG FLEX series firewalls
Zyxel USG FLEX 50(W)
Zyxel USG20(W)-VPN
Zyxel VPN series firewalls
Zyxel ZyWALL/USG series firewalls
Estimated exposure
largetens of thousands of internet-exposed appliances; total installed base plausibly 100,000+ — Public internet scans of Zyxel firewall/VPN and management services consistently show on the order of tens of thousands of exposed devices, and the ATP/USG FLEX/ZyWALL/USG lines have a long, widely deployed installed base that plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.

CISA Known Exploited Vulnerability
Affected
Zyxel Multiple Firewalls
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
zyxel
Products
atp100 firmware, atp200 firmware, atp500 firmware, atp100w firmware, atp700 firmware, atp800 firmware, usg flex 100 firmware, usg flex 50 firmware, usg flex 200 firmware, usg flex 500 firmware, usg flex 700 firmware, usg flex 100w firmware
Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news