CVE-2023-6764
HIGHDescription
A format string vulnerability in a function of the IPSec VPN feature in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, and USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1 could allow an attacker to achieve unauthorized remote code execution by sending a sequence of specially crafted payloads containing an invalid pointer; however, such an attack would require detailed knowledge of an affected device’s memory layout and configuration.
Is your site exposed to CVE-2023-6764?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| zyxel | atp100_firmware |
| zyxel | atp100_firmware |
| zyxel | atp100_firmware |
| zyxel | atp100 |
| zyxel | atp100w_firmware |
| zyxel | atp100w_firmware |
| zyxel | atp100w_firmware |
| zyxel | atp100w |
| zyxel | atp200_firmware |
| zyxel | atp200_firmware |
| zyxel | atp200_firmware |
| zyxel | atp200 |
| zyxel | atp500_firmware |
| zyxel | atp500_firmware |
| zyxel | atp500_firmware |
| zyxel | atp500 |
| zyxel | atp700_firmware |
| zyxel | atp700_firmware |
| zyxel | atp700_firmware |
| zyxel | atp700 |
| zyxel | atp800_firmware |
| zyxel | atp800_firmware |
| zyxel | atp800_firmware |
| zyxel | atp800 |
| zyxel | usg_flex_100_firmware |
| zyxel | usg_flex_100_firmware |
| zyxel | usg_flex_100_firmware |
| zyxel | usg_flex_100 |
| zyxel | usg_flex_100ax_firmware |
| zyxel | usg_flex_100ax_firmware |
| zyxel | usg_flex_100ax_firmware |
| zyxel | usg_flex_100ax |
| zyxel | usg_flex_100h_firmware |
| zyxel | usg_flex_100h_firmware |
| zyxel | usg_flex_100h_firmware |
| zyxel | usg_flex_100h |
| zyxel | usg_flex_100w_firmware |
| zyxel | usg_flex_100w_firmware |
| zyxel | usg_flex_100w_firmware |
| zyxel | usg_flex_100w |
| zyxel | usg_flex_200_firmware |
| zyxel | usg_flex_200_firmware |
| zyxel | usg_flex_200_firmware |
| zyxel | usg_flex_200 |
| zyxel | usg_flex_200h_firmware |
| zyxel | usg_flex_200h_firmware |
| zyxel | usg_flex_200h_firmware |
| zyxel | usg_flex_200h |
| zyxel | usg_flex_200hp_firmware |
| zyxel | usg_flex_200hp_firmware |
| zyxel | usg_flex_200hp_firmware |
| zyxel | usg_flex_200hp |
| zyxel | usg_flex_500_firmware |
| zyxel | usg_flex_500_firmware |
| zyxel | usg_flex_500_firmware |
| zyxel | usg_flex_500 |
| zyxel | usg_flex_500h_firmware |
| zyxel | usg_flex_500h_firmware |
| zyxel | usg_flex_500h_firmware |
| zyxel | usg_flex_500h |
| zyxel | usg_flex_700_firmware |
| zyxel | usg_flex_700_firmware |
| zyxel | usg_flex_700_firmware |
| zyxel | usg_flex_700 |
| zyxel | usg_flex_700h_firmware |
| zyxel | usg_flex_700h_firmware |
| zyxel | usg_flex_700h_firmware |
| zyxel | usg_flex_700h |
| zyxel | usg_flex_50_firmware |
| zyxel | usg_flex_50_firmware |
| zyxel | usg_flex_50_firmware |
| zyxel | usg_flex_50 |
| zyxel | usg_flex_50w_firmware |
| zyxel | usg_flex_50w_firmware |
| zyxel | usg_flex_50w_firmware |
| zyxel | usg_flex_50w |
| zyxel | usg20-vpn_firmware |
| zyxel | usg20-vpn_firmware |
| zyxel | usg20-vpn_firmware |
| zyxel | usg20-vpn |
| zyxel | usg20w-vpn_firmware |
| zyxel | usg20w-vpn_firmware |
| zyxel | usg20w-vpn_firmware |
| zyxel | usg20w-vpn |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-6764? +
How severe is CVE-2023-6764? +
What products are affected by CVE-2023-6764? +
How do I check if I'm vulnerable to CVE-2023-6764? +
Related Vulnerabilities
An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly …
A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort …
An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of …
ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulnerability in its handling of the USER command. By sending …
Solar FTP Server fails to properly handle format strings passed to the USER command. When a specially crafted string containing …
WM Downloader version 3.1.2.2 is vulnerable to a buffer overflow when processing a specially crafted .m3u playlist file. The application …