ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Danish energy sector hit by a wave of coordinated cyberattacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-28771
Unauthenticated OS Command Injection in Zyxel ATP, USG FLEX, VPN, and ZyWALL Firewalls

CVE-2023-28771 is an unauthenticated OS command injection flaw (CWE-78) in Zyxel firewall firmware, caused by improper error message handling in the IKE packet decoder. A remote attacker triggers it by sending crafted packets to an affected device, with no credentials or user interaction required (CVSS 3.1: 9.8, network vector, low complexity). Successful exploitation lets the attacker execute operating-system commands on the firewall, which typically means full device compromise of these perimeter/VPN gateway appliances. Organizations running Zyxel ZyWALL/USG, VPN, USG FLEX, or ATP series firewalls on the affected firmware ranges are exposed, especially where IKE/VPN traffic is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-05-31, carries a 99.3% EPSS score (100th percentile), is reportedly used by DDoS botnets, and was reportedly exploited in the May 2023 coordinated attacks against nearly two dozen Danish energy companies.

Do: Apply Zyxel's patched firmware to all affected devices per the vendor advisory - releases newer than 4.73 for ZyWALL/USG and newer than 5.35 for ATP, USG FLEX, and VPN series - prioritizing internet-facing and VPN gateway appliances, as this is a KEV required-action vulnerability. Where immediate patching is not possible, restrict IKE traffic (UDP 500/4500) to trusted peers or disable unneeded IPsec VPN termination. After patching, review device logs and configurations for signs of command execution or unexpected changes, given confirmed botnet and targeted-attack use.

9.899% KEV PoC
  • Zyxel ZyWALL/USG series firewalls firmware 4.60 through 4.73
  • Zyxel VPN series firewalls firmware 4.60 through 5.35
  • Zyxel USG FLEX series firewalls (USG FLEX 50, 50W, 100, 100W, 200, 500) firmware 4.60 through 5.35
  • +1 more
largetens of thousands of internet-exposed Zyxel firewall/VPN gateways (order of 10,000-100,000 devices/sites); estimate
CVE-2023-33010
+1 in the same advisory: …33009
Buffer Overflow in Zyxel ATP, USG FLEX, VPN and ZyWALL/USG Firewalls Enables RCE

CVE-2023-33010 is a buffer overflow (CWE-120) in the ID processing function of Zyxel's firewall firmware that is triggered when an affected device processes crafted input sent by an unauthenticated attacker. Successful exploitation can cause denial-of-service conditions and, more seriously, allow remote code execution on the firewall itself, giving an attacker a foothold at the network perimeter. The flaw affects multiple Zyxel firewall lines widely used by small and mid-sized organizations, including ATP, USG FLEX, USG FLEX 50(W), USG20(W)-VPN, VPN, and legacy ZyWALL/USG models. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog (added 2023-06-05), indicating it is being exploited in the wild, though no public proof-of-concept is known and ransomware association is unconfirmed. EPSS puts the 30-day exploitation probability at 28.8% (98th percentile), and no CVSS score has been published yet.

Do: Apply the updated firmware for your specific model per Zyxel's security advisory, since the CISA required action is to patch per vendor instructions. Until patched, restrict or disable WAN-side access to the firewall's management/ID processing interfaces and monitor devices for signs of compromise such as unexpected reboots or crashes. Inventory all ATP, USG FLEX (including 50(W)), USG20(W)-VPN, VPN, and ZyWALL/USG units to confirm none remain unpatched.

9.829% KEV
  • Zyxel ATP series firewalls
  • Zyxel USG FLEX firewalls
  • Zyxel USG FLEX 50(W) firewalls
  • +3 more
large≈tens of thousands of internet-exposed devices from a combined installed base likely well over 100,000 across these firewall lines
Full article517 words · extracted from helpnetsecurity.com · click to collapse

The Danish energy sector has suffered what is believed to be the most extensive cyberattack in Danish history, according to SektorCERT.

Danish energy sector under attack

SektorCERT, an organization owned and funded by Danish critical infrastructure (CI) companies, uses a network of 270 sensors implemented across the country and these organizations to monitor internet traffic and detect possible cyberattacks.

From this vantage point, in May 2023, they detected three waves of attacks targeting companies in the energy sector.

The first one started on May 11, when the attackers simultaneously exploited a command injection vulnerability (CVE-2023-28771) in Zyxel firewalls deployed at 16 companies. The attackers gained control of the devices at 11 companies and had access to the critical infrastructure behind it, SektorCERT says. They used the access to grab data about the configuration and active accounts.

Even though CVE-2023-28771 was patched by Zyxell in April 2023, for various reasons the attacked companies did not install the latest updates. The interesting thing, though, is that the attackers knew exactly which companies to hit.

“At this time, information about who had vulnerable devices was not available on public services such as Shodan. Therefore, the attackers had to have obtained information about who had vulnerable firewalls in some other way,” the organization noted, and added that their sensors did not register scans that attackers might have performed prior the attacks.

“The other remarkable thing was that so many companies were attacked at the same time. This kind of coordination requires planning and resources.”

SektorCERT’s incident response team managed to stop the attackers before they could start further exploiting the achieved access.

On May 22, a second wave of attacks started. SektorCERT was alerted by a sensor that one of its member organizations was downloading new firewall software over an insecure connection. This allowed the attackers to include the infrastructure in the Mirai botnet and use it to carry out a DDoS attack against targets in Hong Kong and the US, before the compromised organization disconnected from the internet and went into “island mode” (i.e., isolated from the national electricity distribution network.)

SektorCERT researchers believe that, during the second wave, the attackers also exploited two new vulnerabilities (CVE-2023-33009 and CVE-2023-33010) that Zyxel disclosed and patched a few days later (May 24).

Possible Sandworm involvement

A series of additional attacks went on until May 24, when SektorCERT has been alerted of network traffic to one of the compromised organizations coming from an IP previously used by the Sandworm APT, which has been known to target the Ukrainian energy grid for many years.

“Whether Sandworm was involved in the attack cannot be said with certainty. Individual indicators of this have been observed, but we have no opportunity to neither confirm nor deny it,” SektorCERT said.

It is likely that some of the attacks were simply opportunistic, while others might have had a more sinister goal. But none of them affected the operation of the Danish power grid.

SektorCERT has provided indicators of compromise (IoCs) and offered 25 recommendations for technical and organizational measures that organizations should implement to keep their networks safe.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/11/14/danish-energy-sector-cyberattack/