First published: Mon Apr 24 2023(Updated: )
A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32, and VPN series firmware versions 5.00 through 5.35, which could allow a remote unauthenticated attacker to cause a core dump with a request error message on a vulnerable device by uploading a crafted configuration file.
Credit: security@zyxel.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Zyxel USG Flex 100 firmware | >=5.00<=5.32 | |
Zyxel USG FLEX 100 | ||
Zyxel USG FLEX 100w firmware | >=5.00<=5.32 | |
Zyxel USG FLEX 100w firmware | ||
Zyxel USG FLEX 200 | >=5.00<=5.32 | |
Zyxel USG FLEX 200 firmware | ||
Zyxel USG FLEX 50(W) series firmware | >=5.00<=5.32 | |
Zyxel USG FLEX 50 | ||
Zyxel USG FLEX 50w | >=5.10<=5.32 | |
Zyxel USG FLEX 50(W) series firmware | ||
Zyxel USG FLEX 500 | >=5.00<=5.32 | |
Zyxel USG FLEX 500 firmware | ||
Zyxel USG FLEX firmware | >=5.00<=5.32 | |
Zyxel USG FLEX 700 firmware | ||
Zyxel VPN100 | >=5.00<=5.35 | |
Zyxel VPN100 Firmware | ||
Zyxel VPN1000 Firmware | >=5.00<=5.35 | |
Zyxel VPN1000 Firmware | ||
Zyxel Zywall VPN 300 Firmware | >=5.00<=5.35 | |
Zyxel Zywall VPN300 | ||
Zyxel Zywall VPN 50 Firmware | >=5.00<=5.35 | |
Zyxel VPN50 Firmware | ||
Zyxel USG 20w-VPN Firmware | >=5.10<=5.32 | |
Zyxel USG20 | ||
Zyxel ZyWall ATP100 Firmware | >=5.10<=5.32 | |
Zyxel ATP100 Firmware | ||
Zyxel ATP100W Firmware | >=5.10<=5.32 | |
Zyxel ATP100W Firmware | ||
Zyxel ATP200 firmware | >=5.10<=5.32 | |
Zyxel ATP200 firmware | ||
Zyxel ATP500 Firmware | >=5.10<=5.32 | |
Zyxel ATP500 Firmware | ||
Zyxel Zywall ATP700 Firmware | >=5.10<=5.32 | |
Zyxel ATP700 Firmware | ||
Zyxel ATP800 | >=5.10<=5.32 | |
Zyxel ATP800 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-22917.
The severity level of CVE-2023-22917 is high (7.5).
The Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32, and VPN series firmware versions 5.00 through 5.35 are affected by CVE-2023-22917.
CVE-2023-22917 is a buffer overflow vulnerability in the 'sdwan_iface_ipc' binary of Zyxel ATP series and other affected firmware versions.
Yes, Zyxel has released firmware updates to fix the CVE-2023-22917 vulnerability. Please refer to the Zyxel Security Advisory for more information.