Vulnerability Details CVE-2023-6764
A format string vulnerability in a function of the IPSec VPN feature in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, and USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1 could allow an attacker to achieve unauthorized remote code execution by sending a sequence of specially crafted payloads containing an invalid pointer; however, such an attack would require detailed knowledge of an affected device’s memory layout and configuration.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.4%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2023-6764
-
-
cpe:2.3:h:zyxel:atp100w:-
-
-
-
-
-
cpe:2.3:h:zyxel:usg20-vpn:-
-
cpe:2.3:h:zyxel:usg20w-vpn:-
-
cpe:2.3:h:zyxel:usg_flex_100:-
-
cpe:2.3:h:zyxel:usg_flex_100ax:-
-
cpe:2.3:h:zyxel:usg_flex_100h:-
-
cpe:2.3:h:zyxel:usg_flex_100w:-
-
cpe:2.3:h:zyxel:usg_flex_200:-
-
cpe:2.3:h:zyxel:usg_flex_200h:-
-
cpe:2.3:h:zyxel:usg_flex_200hp:-
-
cpe:2.3:h:zyxel:usg_flex_500:-
-
cpe:2.3:h:zyxel:usg_flex_500h:-
-
cpe:2.3:h:zyxel:usg_flex_50:-
-
cpe:2.3:h:zyxel:usg_flex_50w:-
-
cpe:2.3:h:zyxel:usg_flex_700:-
-
cpe:2.3:h:zyxel:usg_flex_700h:-
-
cpe:2.3:o:zyxel:atp100_firmware:4.32
-
cpe:2.3:o:zyxel:atp100_firmware:4.35
-
cpe:2.3:o:zyxel:atp100_firmware:4.35(abps.2)c0
-
cpe:2.3:o:zyxel:atp100_firmware:4.35(abps.3)c0
-
cpe:2.3:o:zyxel:atp100_firmware:4.60
-
cpe:2.3:o:zyxel:atp100_firmware:5.10
-
cpe:2.3:o:zyxel:atp100_firmware:5.20
-
cpe:2.3:o:zyxel:atp100_firmware:5.30
-
cpe:2.3:o:zyxel:atp100_firmware:5.31
-
cpe:2.3:o:zyxel:atp100_firmware:5.35
-
cpe:2.3:o:zyxel:atp100_firmware:5.36
-
cpe:2.3:o:zyxel:atp100_firmware:5.37
-
cpe:2.3:o:zyxel:atp100w_firmware:4.32
-
cpe:2.3:o:zyxel:atp100w_firmware:4.60
-
cpe:2.3:o:zyxel:atp100w_firmware:5.10
-
cpe:2.3:o:zyxel:atp100w_firmware:5.20
-
cpe:2.3:o:zyxel:atp100w_firmware:5.30
-
cpe:2.3:o:zyxel:atp100w_firmware:5.35
-
cpe:2.3:o:zyxel:atp100w_firmware:5.36
-
cpe:2.3:o:zyxel:atp100w_firmware:5.37
-
cpe:2.3:o:zyxel:atp200_firmware:4.32
-
cpe:2.3:o:zyxel:atp200_firmware:4.35
-
cpe:2.3:o:zyxel:atp200_firmware:4.35(abfw.3)c0
-
cpe:2.3:o:zyxel:atp200_firmware:4.60
-
cpe:2.3:o:zyxel:atp200_firmware:5.10
-
cpe:2.3:o:zyxel:atp200_firmware:5.20
-
cpe:2.3:o:zyxel:atp200_firmware:5.30
-
cpe:2.3:o:zyxel:atp200_firmware:5.35
-
cpe:2.3:o:zyxel:atp200_firmware:5.36
-
cpe:2.3:o:zyxel:atp200_firmware:5.37
-
cpe:2.3:o:zyxel:atp500_firmware:4.32
-
cpe:2.3:o:zyxel:atp500_firmware:4.35
-
cpe:2.3:o:zyxel:atp500_firmware:4.35(abfu.3)c0
-
cpe:2.3:o:zyxel:atp500_firmware:4.60
-
cpe:2.3:o:zyxel:atp500_firmware:5.10
-
cpe:2.3:o:zyxel:atp500_firmware:5.20
-
cpe:2.3:o:zyxel:atp500_firmware:5.30
-
cpe:2.3:o:zyxel:atp500_firmware:5.35
-
cpe:2.3:o:zyxel:atp500_firmware:5.36
-
cpe:2.3:o:zyxel:atp500_firmware:5.37
-
cpe:2.3:o:zyxel:atp700_firmware:4.32
-
cpe:2.3:o:zyxel:atp700_firmware:4.60
-
cpe:2.3:o:zyxel:atp700_firmware:5.10
-
cpe:2.3:o:zyxel:atp700_firmware:5.20
-
cpe:2.3:o:zyxel:atp700_firmware:5.30
-
cpe:2.3:o:zyxel:atp700_firmware:5.35
-
cpe:2.3:o:zyxel:atp700_firmware:5.36
-
cpe:2.3:o:zyxel:atp700_firmware:5.37
-
cpe:2.3:o:zyxel:atp800_firmware:4.32
-
cpe:2.3:o:zyxel:atp800_firmware:4.35
-
cpe:2.3:o:zyxel:atp800_firmware:4.35(abiq.3)c0
-
cpe:2.3:o:zyxel:atp800_firmware:4.60
-
cpe:2.3:o:zyxel:atp800_firmware:5.10
-
cpe:2.3:o:zyxel:atp800_firmware:5.20
-
cpe:2.3:o:zyxel:atp800_firmware:5.30
-
cpe:2.3:o:zyxel:atp800_firmware:5.35
-
cpe:2.3:o:zyxel:atp800_firmware:5.36
-
cpe:2.3:o:zyxel:atp800_firmware:5.37
-
cpe:2.3:o:zyxel:usg20-vpn_firmware:4.16
-
cpe:2.3:o:zyxel:usg20-vpn_firmware:4.31
-
cpe:2.3:o:zyxel:usg20-vpn_firmware:4.35
-
cpe:2.3:o:zyxel:usg20-vpn_firmware:4.35(abaq.3)c0
-
cpe:2.3:o:zyxel:usg20-vpn_firmware:4.60
-
cpe:2.3:o:zyxel:usg20-vpn_firmware:5.01
-
cpe:2.3:o:zyxel:usg20-vpn_firmware:5.10
-
cpe:2.3:o:zyxel:usg20-vpn_firmware:5.36
-
cpe:2.3:o:zyxel:usg20-vpn_firmware:5.37
-
cpe:2.3:o:zyxel:usg20w-vpn_firmware:4.16
-
cpe:2.3:o:zyxel:usg20w-vpn_firmware:4.31
-
cpe:2.3:o:zyxel:usg20w-vpn_firmware:4.35
-
cpe:2.3:o:zyxel:usg20w-vpn_firmware:4.35(abar.3)c0
-
cpe:2.3:o:zyxel:usg20w-vpn_firmware:4.60
-
cpe:2.3:o:zyxel:usg20w-vpn_firmware:5.01
-
cpe:2.3:o:zyxel:usg20w-vpn_firmware:5.10
-
cpe:2.3:o:zyxel:usg20w-vpn_firmware:5.30
-
cpe:2.3:o:zyxel:usg20w-vpn_firmware:5.37
-
cpe:2.3:o:zyxel:usg_flex_100_firmware:4.50
-
cpe:2.3:o:zyxel:usg_flex_100_firmware:4.60
-
cpe:2.3:o:zyxel:usg_flex_100_firmware:5.00
-
cpe:2.3:o:zyxel:usg_flex_100_firmware:5.01
-
cpe:2.3:o:zyxel:usg_flex_100_firmware:5.10
-
cpe:2.3:o:zyxel:usg_flex_100_firmware:5.20
-
cpe:2.3:o:zyxel:usg_flex_100_firmware:5.35
-
cpe:2.3:o:zyxel:usg_flex_100_firmware:5.36
-
cpe:2.3:o:zyxel:usg_flex_100_firmware:5.37
-
cpe:2.3:o:zyxel:usg_flex_100ax_firmware:4.50
-
cpe:2.3:o:zyxel:usg_flex_100ax_firmware:5.37
-
cpe:2.3:o:zyxel:usg_flex_100h_firmware:4.50
-
cpe:2.3:o:zyxel:usg_flex_100h_firmware:5.10
-
cpe:2.3:o:zyxel:usg_flex_100h_firmware:5.37
-
cpe:2.3:o:zyxel:usg_flex_100w_firmware:4.50
-
cpe:2.3:o:zyxel:usg_flex_100w_firmware:4.60
-
cpe:2.3:o:zyxel:usg_flex_100w_firmware:5.00
-
cpe:2.3:o:zyxel:usg_flex_100w_firmware:5.01
-
cpe:2.3:o:zyxel:usg_flex_100w_firmware:5.10
-
cpe:2.3:o:zyxel:usg_flex_100w_firmware:5.30
-
cpe:2.3:o:zyxel:usg_flex_100w_firmware:5.35
-
cpe:2.3:o:zyxel:usg_flex_100w_firmware:5.36
-
cpe:2.3:o:zyxel:usg_flex_100w_firmware:5.37
-
cpe:2.3:o:zyxel:usg_flex_200_firmware:4.50
-
cpe:2.3:o:zyxel:usg_flex_200_firmware:4.60
-
cpe:2.3:o:zyxel:usg_flex_200_firmware:5.00
-
cpe:2.3:o:zyxel:usg_flex_200_firmware:5.01
-
cpe:2.3:o:zyxel:usg_flex_200_firmware:5.20
-
cpe:2.3:o:zyxel:usg_flex_200_firmware:5.30
-
cpe:2.3:o:zyxel:usg_flex_200_firmware:5.35
-
cpe:2.3:o:zyxel:usg_flex_200_firmware:5.36
-
cpe:2.3:o:zyxel:usg_flex_200_firmware:5.37
-
cpe:2.3:o:zyxel:usg_flex_200h_firmware:4.50
-
cpe:2.3:o:zyxel:usg_flex_200h_firmware:5.10
-
cpe:2.3:o:zyxel:usg_flex_200h_firmware:5.37
-
cpe:2.3:o:zyxel:usg_flex_200hp_firmware:4.50
-
cpe:2.3:o:zyxel:usg_flex_200hp_firmware:5.10
-
cpe:2.3:o:zyxel:usg_flex_200hp_firmware:5.37
-
cpe:2.3:o:zyxel:usg_flex_500_firmware:4.50
-
cpe:2.3:o:zyxel:usg_flex_500_firmware:4.60
-
cpe:2.3:o:zyxel:usg_flex_500_firmware:5.00
-
cpe:2.3:o:zyxel:usg_flex_500_firmware:5.01
-
cpe:2.3:o:zyxel:usg_flex_500_firmware:5.10
-
cpe:2.3:o:zyxel:usg_flex_500_firmware:5.20
-
cpe:2.3:o:zyxel:usg_flex_500_firmware:5.30
-
cpe:2.3:o:zyxel:usg_flex_500_firmware:5.35
-
cpe:2.3:o:zyxel:usg_flex_500_firmware:5.36
-
cpe:2.3:o:zyxel:usg_flex_500_firmware:5.37
-
cpe:2.3:o:zyxel:usg_flex_500h_firmware:4.50
-
cpe:2.3:o:zyxel:usg_flex_500h_firmware:5.10
-
cpe:2.3:o:zyxel:usg_flex_500h_firmware:5.37
-
cpe:2.3:o:zyxel:usg_flex_50_firmware:4.16
-
cpe:2.3:o:zyxel:usg_flex_50_firmware:4.50
-
cpe:2.3:o:zyxel:usg_flex_50_firmware:4.60
-
cpe:2.3:o:zyxel:usg_flex_50_firmware:5.00
-
cpe:2.3:o:zyxel:usg_flex_50_firmware:5.10
-
cpe:2.3:o:zyxel:usg_flex_50_firmware:5.35
-
cpe:2.3:o:zyxel:usg_flex_50_firmware:5.36
-
cpe:2.3:o:zyxel:usg_flex_50_firmware:5.37
-
cpe:2.3:o:zyxel:usg_flex_50w_firmware:4.16
-
cpe:2.3:o:zyxel:usg_flex_50w_firmware:4.50
-
cpe:2.3:o:zyxel:usg_flex_50w_firmware:4.60
-
cpe:2.3:o:zyxel:usg_flex_50w_firmware:5.00
-
cpe:2.3:o:zyxel:usg_flex_50w_firmware:5.10
-
cpe:2.3:o:zyxel:usg_flex_50w_firmware:5.30
-
cpe:2.3:o:zyxel:usg_flex_50w_firmware:5.35
-
cpe:2.3:o:zyxel:usg_flex_50w_firmware:5.36
-
cpe:2.3:o:zyxel:usg_flex_50w_firmware:5.37
-
cpe:2.3:o:zyxel:usg_flex_700_firmware:4.50
-
cpe:2.3:o:zyxel:usg_flex_700_firmware:4.60
-
cpe:2.3:o:zyxel:usg_flex_700_firmware:5.00
-
cpe:2.3:o:zyxel:usg_flex_700_firmware:5.10
-
cpe:2.3:o:zyxel:usg_flex_700_firmware:5.20
-
cpe:2.3:o:zyxel:usg_flex_700_firmware:5.30
-
cpe:2.3:o:zyxel:usg_flex_700_firmware:5.35
-
cpe:2.3:o:zyxel:usg_flex_700_firmware:5.36
-
cpe:2.3:o:zyxel:usg_flex_700_firmware:5.37
-
cpe:2.3:o:zyxel:usg_flex_700h_firmware:4.50
-
cpe:2.3:o:zyxel:usg_flex_700h_firmware:5.10
-
cpe:2.3:o:zyxel:usg_flex_700h_firmware:5.37