CVE-2023-34140: Buffer Overflow
A buffer overflow vulnerability in the Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series firmware versions 4.50 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 4.16 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 4.16 through 5.36 Patch 2, VPN series firmware versions 4.30 through 5.36 Patch 2, NXC2500 firmware versions 6.10(AAIG.0) through 6.10(AAIG.3), and NXC5500 firmware versions 6.10(AAOS.0) through 6.10(AAOS.4), could allow an unauthenticated, LAN-based attacker to cause denial of service (DoS) conditions by sending a crafted request to the CAPWAP daemon.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zyxel ATP series firmwareto a version that resolves this vulnerability.Fixed in 5.36 Patch 2 - Upgrade
Upgrade
USG FLEX series firmwareto a version that resolves this vulnerability.Fixed in 5.36 Patch 2 - Upgrade
Upgrade
USG FLEX 50(W) series firmwareto a version that resolves this vulnerability.Fixed in 5.36 Patch 2 - Upgrade
Upgrade
USG20(W)-VPN series firmwareto a version that resolves this vulnerability.Fixed in 5.36 Patch 2 - Upgrade
Upgrade
VPN series firmwareto a version that resolves this vulnerability.Fixed in 5.36 Patch 2 - Upgrade
Upgrade
NXC2500 firmwareto a version that resolves this vulnerability.Fixed in 6.10(AAIG.3) - Upgrade
Upgrade
NXC5500 firmwareto a version that resolves this vulnerability.Fixed in 6.10(AAOS.4)
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34140?
The severity of CVE-2023-34140 is medium with a score of 6.5.
Which Zyxel products are affected by CVE-2023-34140?
Zyxel ATP series firmware versions 4.32 through 5.36 Patch 2, USG FLEX series firmware versions 4.50 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 4.16 through 5.36 Patch 2, and USG20(W)-VPN series firmware versions 4.16 through 5.36 Patch 2 are affected by CVE-2023-34140.
How can I fix CVE-2023-34140?
To fix CVE-2023-34140, update your Zyxel firmware to versions 5.37 for affected models.
What is the Common Vulnerabilities and Exposures (CVE) ID of this vulnerability?
The Common Vulnerabilities and Exposures (CVE) ID of this vulnerability is CVE-2023-34140.