Summary:
The vulnerability, known as CVE-2023-28771 with a CVSS score of 9.8, can be leveraged remotely to run operating system commands. A lack of proper error message handling in certain versions of a firewall can permit an unauthorized attacker to remotely execute operating system commands through the transmission of manipulated packets to a vulnerable device. To ensure the security of their systems, it is strongly recommended that users update their firewalls without delay.[/subscribe_to_unlock_form]
Summary:
The vulnerability, known as CVE-2023-28771 with a CVSS score of 9.8, can be leveraged remotely to run operating system commands. A lack of proper error message handling in certain versions of a firewall can permit an unauthorized attacker to remotely execute operating system commands through the transmission of manipulated packets to a vulnerable device. To ensure the security of their systems, it is strongly recommended that users update their firewalls without delay.[emaillocker id="1283"]
Although there is no evidence of the vulnerability being exploited in any malicious attacks, it is known that malicious actors target unpatched Zyxel appliances. The affected firmware versions for the bug are 4.60 to 5.35 for ATP, USG FLEX, and VPN, and 4.60 to 4.73 for ZyWALL/USG. Fixes have been provided in ATP, USG FLEX, and VPN firmware releases 5.36, and in ZyWALL/USG firmware version 4.73 Patch 1.
High-severity command injection vulnerability, tracked as CVE-2023-27991, has also been fixed in the firmware updates for ATP, USG FLEX, and VPN firewalls. The USG FLEX 50(W) / USG20(W)-VPN firewalls have also been patched with firmware version 5.36 to address the issue. Earlier this week, the vendor released patches for several high-severity vulnerabilities affecting various models of firewalls and access points. These flaws could allow attackers to cause DoS conditions, execute commands, retrieve encrypted administrator information, or trigger a core dump. Zyxel has addressed the vulnerabilities affecting the affected firewalls by releasing firmware updates. Additionally, firmware updates have been released for multiple AP devices, while hotfixes are available for others upon request.
Recommendations:
References:
The following reports contain further technical details:
https://www.securityweek.com/critical-vulnerability-in-zyxel-firewalls-leads-to-command-execution/
[/emaillocker]