CVE-2023-6764
HIGHDescription
A format string vulnerability in a function of the IPSec VPN feature in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, and USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1 could allow an attacker to achieve unauthorized remote code execution by sending a sequence of specially crafted payloads containing an invalid pointer; however, such an attack would require detailed knowledge of an affected device’s memory layout and configuration.
Is your site exposed to CVE-2023-6764?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| zyxel | atp100_firmware |
| zyxel | atp100_firmware |
| zyxel | atp100_firmware |
| zyxel | atp100 |
| zyxel | atp100w_firmware |
| zyxel | atp100w_firmware |
| zyxel | atp100w_firmware |
| zyxel | atp100w |
| zyxel | atp200_firmware |
| zyxel | atp200_firmware |
| zyxel | atp200_firmware |
| zyxel | atp200 |
| zyxel | atp500_firmware |
| zyxel | atp500_firmware |
| zyxel | atp500_firmware |
| zyxel | atp500 |
| zyxel | atp700_firmware |
| zyxel | atp700_firmware |
| zyxel | atp700_firmware |
| zyxel | atp700 |
| zyxel | atp800_firmware |
| zyxel | atp800_firmware |
| zyxel | atp800_firmware |
| zyxel | atp800 |
| zyxel | usg_flex_100_firmware |
| zyxel | usg_flex_100_firmware |
| zyxel | usg_flex_100_firmware |
| zyxel | usg_flex_100 |
| zyxel | usg_flex_100ax_firmware |
| zyxel | usg_flex_100ax_firmware |
| zyxel | usg_flex_100ax_firmware |
| zyxel | usg_flex_100ax |
| zyxel | usg_flex_100h_firmware |
| zyxel | usg_flex_100h_firmware |
| zyxel | usg_flex_100h_firmware |
| zyxel | usg_flex_100h |
| zyxel | usg_flex_100w_firmware |
| zyxel | usg_flex_100w_firmware |
| zyxel | usg_flex_100w_firmware |
| zyxel | usg_flex_100w |
| zyxel | usg_flex_200_firmware |
| zyxel | usg_flex_200_firmware |
| zyxel | usg_flex_200_firmware |
| zyxel | usg_flex_200 |
| zyxel | usg_flex_200h_firmware |
| zyxel | usg_flex_200h_firmware |
| zyxel | usg_flex_200h_firmware |
| zyxel | usg_flex_200h |
| zyxel | usg_flex_200hp_firmware |
| zyxel | usg_flex_200hp_firmware |
| zyxel | usg_flex_200hp_firmware |
| zyxel | usg_flex_200hp |
| zyxel | usg_flex_500_firmware |
| zyxel | usg_flex_500_firmware |
| zyxel | usg_flex_500_firmware |
| zyxel | usg_flex_500 |
| zyxel | usg_flex_500h_firmware |
| zyxel | usg_flex_500h_firmware |
| zyxel | usg_flex_500h_firmware |
| zyxel | usg_flex_500h |
| zyxel | usg_flex_700_firmware |
| zyxel | usg_flex_700_firmware |
| zyxel | usg_flex_700_firmware |
| zyxel | usg_flex_700 |
| zyxel | usg_flex_700h_firmware |
| zyxel | usg_flex_700h_firmware |
| zyxel | usg_flex_700h_firmware |
| zyxel | usg_flex_700h |
| zyxel | usg_flex_50_firmware |
| zyxel | usg_flex_50_firmware |
| zyxel | usg_flex_50_firmware |
| zyxel | usg_flex_50 |
| zyxel | usg_flex_50w_firmware |
| zyxel | usg_flex_50w_firmware |
| zyxel | usg_flex_50w_firmware |
| zyxel | usg_flex_50w |
| zyxel | usg20-vpn_firmware |
| zyxel | usg20-vpn_firmware |
| zyxel | usg20-vpn_firmware |
| zyxel | usg20-vpn |
| zyxel | usg20w-vpn_firmware |
| zyxel | usg20w-vpn_firmware |
| zyxel | usg20w-vpn_firmware |
| zyxel | usg20w-vpn |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-6764? +
How severe is CVE-2023-6764? +
What products are affected by CVE-2023-6764? +
How do I check if I'm vulnerable to CVE-2023-6764? +
Related Vulnerabilities
Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary …
An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of …
An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly …
Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. This issue affects Connext …
In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan …
ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulnerability in its handling of the USER command. By sending …