

Zyxel firewalls affected by two new security flaws, patches must be installed as...
source link: https://www.techspot.com/news/98842-zyxel-firewalls-affected-two-new-security-flaws-patches.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

Zyxel firewalls affected by two new security flaws, patches must be installed asap
The critical vulnerabilities can be abused for remote code execution or DoS attacks
By Alfonso Maruccia 43 minutes ago
What just happened? Taiwanese networking corporation Zyxel is once again facing a potential security crisis, as many of the company's firewalls are affected by a couple of nasty vulnerabilities. Updated firmware versions are already available, and customers are strongly advised to install them as soon as possible.
The latest security advisory issued by Zyxel is warning customers about multiple buffer overflow vulnerabilities discovered in several of the company's firewall and VPN devices. The Taiwan-based manufacturer says that the two flaws can be potentially abused by attackers to execute malicious code or breach through vulnerable networks.
The first security flaw included in Zyxel's advisory is tracked as CVE-2023-33009, and is described as a buffer overflow issue in the notification function in Zyxel ATP series firmware. The flaw could allow an unauthenticated attacker to bring a denial-of-service (DoS) threat against vulnerable appliances, or even to remotely execute malicious code on the affected firewall device.
The second flaw is tracked as CVE-2023-33010, which is a buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware. The flaw could once again allow an unauthenticated attacker to cause "denial-of-service (DoS) conditions," or to remotely execute code on an affected device. Both the issues are classified as "critical" vulnerabilities, with a severity score of 9.8.

A buffer overflow condition occurs when a program (or a program's sub-routine) is somewhat able to write data to a buffer beyond the buffer's allocated memory, overwriting adjacent memory locations. The issue is typically "solved" with a system crash or by showing an error message, yet sometimes the buffer overflow condition can be exploited by talented hackers or cyber-criminals to execute code or defeat security measures.
After a "thorough" internal investigation, Zyxel said it identified the firewall series affected by the aforementioned critical vulnerabilities. The devices which are within their "vulnerability support period," Zyxel said, include the following series:
- ATP, firmware versions ZLD V4.32 to V5.36 Patch 1
- USG FLEX, firmware versions ZLD V4.50 to V5.36 Patch 1
- USG FLEX50(W) / USG20(W)-VPN, firmware versions ZLD V4.25 to V5.36 Patch 1
- VPN, firmware versions ZLD V4.30 to V5.36 Patch 1
- ZyWALL/USG, firmware versions ZLD V4.25 to V4.73 Patch 1
Zyxel has already released updated firmware builds to patch the two critical vulnerabilities, and customers should of course install the updates as soon as possible to avoid being targeted by attackers. Black hat hackers and cyber-criminals are always searching for vulnerable devices to breach networks belonging to private or public organizations, and they are usually pretty good at finding them.
Recommend
-
8
Quick Tip - Get All The Security Patches Installed On A Server Since A Specific Date Recently, I needed to get a list of all the security patches I’d installed on a group of servers in the last year. It turns out that th...
-
8
Hackers can exploit network security devices Customers are warned by Zyxel of various attacks on numerous firewalls and devices. Whether the vulnerabilities are new and the number of customers affec...
-
7
INCOMING — Hackers are using unknown user accounts to target Zyxel firewalls and VPNs Authentication bypass attacks allow hackers to change breach network security. ...
-
6
GOT PATCHES? — Zyxel patches critical vulnerability that can allow Firewall and VPN hijacks Hackers can exploit authentication bypass flaw to gain administrative control....
-
10
This Latest Windows Update Patches A Monstrous Amount Of Flaws ...
-
3
QNAP's NAS devices affected by a new critical security issue, patches are available The next ransomware target for cyber-crime gangs? By
-
8
GOT PATCHES? — Researchers tell owners to “assume compromise” of unpatched Zyxel firewalls Poor patching hygiene is fueling a flurry of "downstream attacks" on other target...
-
13
News Analysis MOVEit Transfer developer patches more critical flaws after security audit...
-
10
Apple patches two actively exploited security flaws with iOS 16.5.1 and more
-
8
Critical security flaw discovered in Zyxel NAS devices, patches are already available No mitigations or temporary remediations this time. Just a firmware update you have to install ASA...
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK