Zyxel Customers Urged to Patch Exploited Bug

The security community is urging users of Zyxel networking devices to update their firewalls and VPNs after reports that hackers are actively exploiting vulnerabilities to allow remote code execution.

The Taiwanese vendor fixed CVE-2023-28771 on April 25th and said the flaw affected versions ZLD V4.60 through V5.35 of their ATP, USG Flex, VPN and ZyWall/USG products clarified. For ZyWall/USG products, it affects versions ZLD V4.60 to V4.73.

“Improper handling of error messages in some firewall versions could allow an unauthenticated attacker to remotely execute some OS commands by sending crafted packets to an affected device. there is,” warned Zyxel in the recommendation.

For more information on Zyxel security risks, see Over 20,000 Zyxel firewalls still exposed to critical bugs.

In a blog post yesterday, Rapid7 explained that the bug exists in the default settings of vulnerable devices and is exploitable on wide area network (WAN) interfaces designed to be exposed to the Internet.

“Successful exploitation of CVE-2023-28771 allows an unauthenticated attacker to remotely execute code on the target system by sending specially crafted IKEv2 packets to UDP port 500 on the device. It is possible,” the report added.

Rapid7 warned that the CVE was “widely exploited” to compromise devices and recruit them into Mirai-based botnets, possibly in DDoS attacks.

To further demonstrate the potential impact of this vulnerability, the US Cybersecurity and Infrastructure Security Agency (CISA) has added a CVE to its catalog of known exploited vulnerabilities.

That means private federal agencies have until June 21 to patch, but non-governmental organizations are also being asked to take action against the vulnerabilities listed in the catalog.

As if that wasn’t enough for Zyxel customers, last week the company also released an advisory for two new vulnerabilities (CVE-2023-33009 and CVE-2023-33010). According to Rapid 7, these are buffer overflow vulnerabilities that allow an unauthenticated attacker to “cause her DoS condition or execute arbitrary code on the affected device.” It is said that there is.

Editorial image credit: Postmodern Studio / Shutterstock.com

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *