CVE-2023-6764
HIGHDescription
A format string vulnerability in a function of the IPSec VPN feature in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, and USG20(W)-VPN series firmware versions from 4.16 through 5.37 Patch 1 could allow an attacker to achieve unauthorized remote code execution by sending a sequence of specially crafted payloads containing an invalid pointer; however, such an attack would require detailed knowledge of an affected device’s memory layout and configuration.
Is your site exposed to CVE-2023-6764?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| zyxel | atp100_firmware |
| zyxel | atp100_firmware |
| zyxel | atp100_firmware |
| zyxel | atp100 |
| zyxel | atp100w_firmware |
| zyxel | atp100w_firmware |
| zyxel | atp100w_firmware |
| zyxel | atp100w |
| zyxel | atp200_firmware |
| zyxel | atp200_firmware |
| zyxel | atp200_firmware |
| zyxel | atp200 |
| zyxel | atp500_firmware |
| zyxel | atp500_firmware |
| zyxel | atp500_firmware |
| zyxel | atp500 |
| zyxel | atp700_firmware |
| zyxel | atp700_firmware |
| zyxel | atp700_firmware |
| zyxel | atp700 |
| zyxel | atp800_firmware |
| zyxel | atp800_firmware |
| zyxel | atp800_firmware |
| zyxel | atp800 |
| zyxel | usg_flex_100_firmware |
| zyxel | usg_flex_100_firmware |
| zyxel | usg_flex_100_firmware |
| zyxel | usg_flex_100 |
| zyxel | usg_flex_100ax_firmware |
| zyxel | usg_flex_100ax_firmware |
| zyxel | usg_flex_100ax_firmware |
| zyxel | usg_flex_100ax |
| zyxel | usg_flex_100h_firmware |
| zyxel | usg_flex_100h_firmware |
| zyxel | usg_flex_100h_firmware |
| zyxel | usg_flex_100h |
| zyxel | usg_flex_100w_firmware |
| zyxel | usg_flex_100w_firmware |
| zyxel | usg_flex_100w_firmware |
| zyxel | usg_flex_100w |
| zyxel | usg_flex_200_firmware |
| zyxel | usg_flex_200_firmware |
| zyxel | usg_flex_200_firmware |
| zyxel | usg_flex_200 |
| zyxel | usg_flex_200h_firmware |
| zyxel | usg_flex_200h_firmware |
| zyxel | usg_flex_200h_firmware |
| zyxel | usg_flex_200h |
| zyxel | usg_flex_200hp_firmware |
| zyxel | usg_flex_200hp_firmware |
| zyxel | usg_flex_200hp_firmware |
| zyxel | usg_flex_200hp |
| zyxel | usg_flex_500_firmware |
| zyxel | usg_flex_500_firmware |
| zyxel | usg_flex_500_firmware |
| zyxel | usg_flex_500 |
| zyxel | usg_flex_500h_firmware |
| zyxel | usg_flex_500h_firmware |
| zyxel | usg_flex_500h_firmware |
| zyxel | usg_flex_500h |
| zyxel | usg_flex_700_firmware |
| zyxel | usg_flex_700_firmware |
| zyxel | usg_flex_700_firmware |
| zyxel | usg_flex_700 |
| zyxel | usg_flex_700h_firmware |
| zyxel | usg_flex_700h_firmware |
| zyxel | usg_flex_700h_firmware |
| zyxel | usg_flex_700h |
| zyxel | usg_flex_50_firmware |
| zyxel | usg_flex_50_firmware |
| zyxel | usg_flex_50_firmware |
| zyxel | usg_flex_50 |
| zyxel | usg_flex_50w_firmware |
| zyxel | usg_flex_50w_firmware |
| zyxel | usg_flex_50w_firmware |
| zyxel | usg_flex_50w |
| zyxel | usg20-vpn_firmware |
| zyxel | usg20-vpn_firmware |
| zyxel | usg20-vpn_firmware |
| zyxel | usg20-vpn |
| zyxel | usg20w-vpn_firmware |
| zyxel | usg20w-vpn_firmware |
| zyxel | usg20w-vpn_firmware |
| zyxel | usg20w-vpn |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-6764? +
How severe is CVE-2023-6764? +
What products are affected by CVE-2023-6764? +
How do I check if I'm vulnerable to CVE-2023-6764? +
Related Vulnerabilities
A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort …
An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of …
In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan …
Solar FTP Server fails to properly handle format strings passed to the USER command. When a specially crafted string containing …
WM Downloader version 3.1.2.2 is vulnerable to a buffer overflow when processing a specially crafted .m3u playlist file. The application …
ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulnerability in its handling of the USER command. By sending …