CVE-2023-33009: Zyxel Multiple Firewalls Buffer Overflow Vulnerability
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.25 through 5.36 Patch 1, VPN series firmware versions 4.30 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.25 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
Other sources
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
Zyxel ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and ZyWALL/USG firewalls contain a buffer overflow vulnerability in the notification function that could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and remote code execution on an affected device.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zyxel ATP series firmwareto a version that resolves this vulnerability.Fixed in 4.32 through 5.36Patch Patch 1 - Upgrade
Upgrade
USG FLEX series firmwareto a version that resolves this vulnerability.Fixed in 4.50 through 5.36Patch Patch 1 - Upgrade
Upgrade
USG FLEX 50(W) firmwareto a version that resolves this vulnerability.Fixed in 4.25 through 5.36Patch Patch 1 - Upgrade
Upgrade
USG20(W)-VPN firmwareto a version that resolves this vulnerability.Fixed in 4.25 through 5.36Patch Patch 1 - Upgrade
Upgrade
VPN series firmwareto a version that resolves this vulnerability.Fixed in 4.30 through 5.36Patch Patch 1 - Upgrade
Upgrade
ZyWALL/USG series firmwareto a version that resolves this vulnerability.Fixed in 4.25 through 4.73Patch Patch 1 - Upgrade
Upgrade
Zyxel ATP series firmwareto a version that resolves this vulnerability.Fixed in 4.60 through 5.36Patch Patch 1 - Upgrade
Upgrade
USG FLEX series firmwareto a version that resolves this vulnerability.Fixed in 4.60 through 5.36Patch Patch 1 - Upgrade
Upgrade
USG FLEX 50(W) firmwareto a version that resolves this vulnerability.Fixed in 4.60 through 5.36Patch Patch 1 - Upgrade
Upgrade
USG20(W)-VPN firmwareto a version that resolves this vulnerability.Fixed in 4.60 through 5.36Patch Patch 1 - Upgrade
Upgrade
VPN series firmwareto a version that resolves this vulnerability.Fixed in 4.60 through 5.36Patch Patch 1 - Upgrade
Upgrade
ZyWALL/USG series firmwareto a version that resolves this vulnerability.Fixed in 4.60 through 4.73Patch Patch 1
Event History
Frequently Asked Questions
What is CVE-2023-33009?
CVE-2023-33009 is a buffer overflow vulnerability in the notification function in Zyxel ATP series, USG FLEX series, USG FLEX 50(W), and USG20(W)-VPN firmware versions 4.32 through 5.36 Patch 1.
How does CVE-2023-33009 affect Zyxel Multiple Firewalls?
CVE-2023-33009 affects Zyxel ATP series, USG FLEX series, USG FLEX 50(W), and USG20(W)-VPN firmware versions 4.32 through 5.36 Patch 1, leading to a buffer overflow vulnerability in the notification function.
How severe is CVE-2023-33009?
CVE-2023-33009 is a buffer overflow vulnerability with a severity rating of high.
Is there a patch available for CVE-2023-33009?
Yes, Zyxel has released firmware versions 5.36 Patch 2 and later to address the CVE-2023-33009 vulnerability.
What should I do to fix CVE-2023-33009?
To fix CVE-2023-33009, update your Zyxel firewall's firmware to version 5.36 Patch 2 or later.