← לוח פגיעויות

CVE-2023-33009

קריטית 9.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Zyxel Multiple Firewalls Buffer Overflow Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
28% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-120

מוצרים מושפעים

zyxel: atp100 firmware; zyxel: atp100; zyxel: atp200 firmware; zyxel: atp200; zyxel: atp500 firmware; zyxel: atp500; zyxel: atp100w firmware; zyxel: atp100w; zyxel: atp700 firmware; zyxel: atp700; zyxel: atp800 firmware; zyxel: atp800; zyxel: usg flex 100 firmware; zyxel: usg flex 100; zyxel: usg flex 50 firmware

קישורים