CVE-2023-33009
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Zyxel Multiple Firewalls Buffer Overflow Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions 4.60 through 5.36 Patch 1, VPN series firmware versions 4.60 through 5.36 Patch 1, ZyWALL/USG series firmware versions 4.60 through 4.73 Patch 1, could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on an affected device.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 28% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-120
מוצרים מושפעים
zyxel: atp100 firmware; zyxel: atp100; zyxel: atp200 firmware; zyxel: atp200; zyxel: atp500 firmware; zyxel: atp500; zyxel: atp100w firmware; zyxel: atp100w; zyxel: atp700 firmware; zyxel: atp700; zyxel: atp800 firmware; zyxel: atp800; zyxel: usg flex 100 firmware; zyxel: usg flex 100; zyxel: usg flex 50 firmware