Zyxel Vulnerability Exploited by DDoS Botnets on Linux Systems
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-28771 | Unauthenticated OS Command Injection in Zyxel ATP, USG FLEX, VPN, and ZyWALL Firewalls CVE-2023-28771 is an unauthenticated OS command injection flaw (CWE-78) in Zyxel firewall firmware, caused by improper error message handling in the IKE packet decoder. A remote attacker triggers it by sending crafted packets to an affected device, with no credentials or user interaction required (CVSS 3.1: 9.8, network vector, low complexity). Successful exploitation lets the attacker execute operating-system commands on the firewall, which typically means full device compromise of these perimeter/VPN gateway appliances. Organizations running Zyxel ZyWALL/USG, VPN, USG FLEX, or ATP series firewalls on the affected firmware ranges are exposed, especially where IKE/VPN traffic is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-05-31, carries a 99.3% EPSS score (100th percentile), is reportedly used by DDoS botnets, and was reportedly exploited in the May 2023 coordinated attacks against nearly two dozen Danish energy companies. Do: Apply Zyxel's patched firmware to all affected devices per the vendor advisory - releases newer than 4.73 for ZyWALL/USG and newer than 5.35 for ATP, USG FLEX, and VPN series - prioritizing internet-facing and VPN gateway appliances, as this is a KEV required-action vulnerability. Where immediate patching is not possible, restrict IKE traffic (UDP 500/4500) to trusted peers or disable unneeded IPsec VPN termination. After patching, review device logs and configurations for signs of command execution or unexpected changes, given confirmed botnet and targeted-attack use. | 9.8 | 99% | KEV PoC |
| largetens of thousands of internet-exposed Zyxel firewall/VPN gateways (order of 10,000-100,000 devices/sites); estimate |
Full article330 words · extracted from infosecurity-magazine.com · click to collapse
Distributed Denial of Service (DDoS) botnets have been used to actively exploit a critical vulnerability found in Zyxel firewall models.
The flaw, identified by Fortinet security researchers as CVE-2023-28771, explicitly affects Linux platforms.
Exploiting the vulnerability, remote attackers gain unauthorized control over the vulnerable systems, enabling them to conduct DDoS attacks.
Discussing the vulnerability in a blog post published on Wednesday, July 20, Fortinet senior antivirus analyst Cara Lin said it stems from a command injection vulnerability, enabling attackers to execute arbitrary code by sending a specially crafted packet to the targeted Zyxel device.
"The severity of this flaw, rated 9.8 on the CVSS scoring system, was reported by researchers from TRAPA Security," Lin wrote.
After Fortinet's research exposed the vulnerability, Zyxel promptly released a security advisory on April 25, 2023. Despite this, the Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog in May, indicating active exploitation in the wild.
In response to the vulnerability's disclosure, Fortinet observed an uptick in malicious activities, particularly in May. Through the capture of exploit traffic, Fortinet was able to confirm the attacks have been observed in Central America, North America, East Asia, and South Asia.
In particular, Lin said Fortinet discovered Multiple DDoS botnets, including Dark.IoT, a variant based on Mirai, that have been exploiting the vulnerability to launch attacks.
Read more on Mirai malware: New Mirai Variant Campaigns are Targeting IoT Devices
The antivirus analyst recommended organizations using Linux platforms and Zyxel firewalls to prioritize the application of available patches and updates to mitigate the risk.
"To effectively address this threat, it is crucial to prioritize the application of patches and updates whenever possible. Taking proactive measures to ensure the security of these devices is highly recommended."
The new Fortinet advisory comes months after an April analysis by Jason Steer, CISO of Recorded Future, highlighted an increasing number of DDoS attacks in 2023 and how the trend is connected to ransomware gangs.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/zyxel-flaw-exploited-ddos-botnets/