ZeroHour
Ars Technica · Securitypublished ()ingested

Zyxel users still getting hacked by DDoS botnet emerge as public nuisance No. 1

mediumMalwareimportance 35CVE-2023-28771

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-28771
Unauthenticated OS Command Injection in Zyxel ATP, USG FLEX, VPN, and ZyWALL Firewalls

CVE-2023-28771 is an unauthenticated OS command injection flaw (CWE-78) in Zyxel firewall firmware, caused by improper error message handling in the IKE packet decoder. A remote attacker triggers it by sending crafted packets to an affected device, with no credentials or user interaction required (CVSS 3.1: 9.8, network vector, low complexity). Successful exploitation lets the attacker execute operating-system commands on the firewall, which typically means full device compromise of these perimeter/VPN gateway appliances. Organizations running Zyxel ZyWALL/USG, VPN, USG FLEX, or ATP series firewalls on the affected firmware ranges are exposed, especially where IKE/VPN traffic is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-05-31, carries a 99.3% EPSS score (100th percentile), is reportedly used by DDoS botnets, and was reportedly exploited in the May 2023 coordinated attacks against nearly two dozen Danish energy companies.

Do: Apply Zyxel's patched firmware to all affected devices per the vendor advisory - releases newer than 4.73 for ZyWALL/USG and newer than 5.35 for ATP, USG FLEX, and VPN series - prioritizing internet-facing and VPN gateway appliances, as this is a KEV required-action vulnerability. Where immediate patching is not possible, restrict IKE traffic (UDP 500/4500) to trusted peers or disable unneeded IPsec VPN termination. After patching, review device logs and configurations for signs of command execution or unexpected changes, given confirmed botnet and targeted-attack use.

9.899% KEV PoC
  • Zyxel ZyWALL/USG series firewalls firmware 4.60 through 4.73
  • Zyxel VPN series firewalls firmware 4.60 through 5.35
  • Zyxel USG FLEX series firewalls (USG FLEX 50, 50W, 100, 100W, 200, 500) firmware 4.60 through 5.35
  • +1 more
largetens of thousands of internet-exposed Zyxel firewall/VPN gateways (order of 10,000-100,000 devices/sites); estimate
Full article383 words · extracted from arstechnica.com · click to collapse

Organizations that have yet to patch a 9.8-severity vulnerability in network devices made by Zyxel have emerged as public nuisance No. 1 as a sizable number of them continue to be exploited and wrangled into botnets that wage DDoS attacks.

Zyxel patched the flaw on April 25. Five weeks later, Shadowserver, an organization that monitors Internet threats in real time, warned that many Zyxel firewalls and VPN servers had been compromised in attacks that showed no signs of stopping. The Shadowserver assessment at the time was: “If you have a vulnerable device exposed, assume compromise.”

On Wednesday—12 weeks since Zyxel delivered a patch and seven weeks since Shadowserver sounded the alarm—security firm Fortinet published research reporting a surge in exploit activity being carried out by multiple threat actors in recent weeks. As was the case with the active compromises Shadowserver reported, the attacks came overwhelmingly from variants based on Mirai, an open source application hackers use to identify and exploit common vulnerabilities in routers and other Internet of Things devices.

When successful, Mirai corals the devices into botnets that can potentially deliver distributed denial-of-service attacks of enormous sizes.

Increasing the urgency of patching the Zyxel vulnerability, researchers in June published exploit code that anyone could download and incorporate into their own botnet software. Despite the clear and imminent threat, enough vulnerable devices remain even as attacks continue to surge, Fortinet researcher Cara Lin said in Thursday’s report. Lin wrote:

Since the publication of the exploit module, there has been a sustained surge in malicious activity. Analysis conducted by FortiGuard Labs has identified a significant increase in attack bursts starting from May, as depicted in the trigger count graph shown in Figure 1. We also identified multiple botnets, including Dark.IoT, a variant based on Mirai, as well as another botnet that employs customized DDoS attack methods. In this article, we will provide a detailed explanation of the payload delivered through CVE-2023-28771 and associated botnets.

Figure 1: Botnet’s attacking activity. Credit: Fortinet

The vulnerability used to compromise the Zyxel devices, tracked as CVE-2023-28771, is an unauthenticated command-injection vulnerability with a severity rating of 9.8. The flaw can be exploited with a specially crafted IKEv2 packet to UDP port 500 of the device to execute malicious code. Zyxel’s disclosure of the flaw is here.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/07/ddos-botnets-are-still-feeding-on-zyxel-devices-with-vulnerable-critical-flaw/