
Zyxel has released software updates to address two critical security flaws affecting some firewall and VPN products. These flaws could be exploited by a remote attacker to execute code.
Both CVE-2023-33009 and CVE-2023-33010 flaws are buffer overflow vulnerabilities and are rated 9.8 out of 10 on the CVSS scoring system.
A brief description of the two issues follows.
- CVE-2023-33009 – A buffer overflow vulnerability in the notification function could allow an unauthenticated attacker to cause a denial of service (DoS) condition and remote code execution.
- CVE-2023-33010 – A buffer overflow vulnerability in the identity processing functionality could allow an unauthenticated attacker to cause a denial of service (DoS) condition resulting in remote code execution.
The following devices are affected –
- ATP (versions ZLD V4.32 to V5.36 Patch 1, patched in ZLD V5.36 Patch 2)
- USG FLEX (versions ZLD V4.50 – V5.36 Patch 1, patched with ZLD V5.36 Patch 2)
- USG FLEX50(W) / USG20(W)-VPN (version ZLD V4.25 to V5.36 Patch 1, patched with ZLD V5.36 Patch 2)
- VPN (versions ZLD V4.30 through V5.36 Patch 1, patched with ZLD V5.36 Patch 2), and
- ZyWALL/USG (versions ZLD V4.25 – V4.73 Patch 1, patched with ZLD V4.73 Patch 2)
Security researchers at TRAPA Security and STAR Labs SG are credited with discovering and reporting this flaw.
Zero Trust + Deception: Learn How to Outsmart Attackers!
See how Deception can detect advanced threats, stop lateral movement, and strengthen your Zero Trust strategy. Join us for an insightful webinar!
Reserve your seat!
This advisory comes less than a month after Zyxel shipped a fix for another critical security flaw in their firewall devices. This flaw could be exploited for remote code execution on the affected system.
This issue is tracked as CVE-2023-28771 (CVSS score: 9.8) and is also blamed on TRAPA Security, which the network equipment manufacturer claims is due to improper error message handling. Since then, it has been actively exploited by threat actors associated with the Mirai botnet.