Subscribe to Updates

    Get the latest creative news from CRYPTO NOUNCE.

    What's Hot

    NEXT Insurance and Gusto Expand Partnership to Modernize Embedded Payroll Experience

    June 7, 2023

    Business will be able to accept IDs in Apple Wallet with iOS 17, among other changes

    June 7, 2023

    Fable 4 is crucial to Xbox’s future, but it could be a Monkey’s Paw moment for fans

    June 7, 2023
    Facebook Twitter Instagram
    Facebook Twitter Instagram Vimeo
    Cryptonounce.com
    Contact
    • Business
      • Deals
      • investors
      • IPO
      • Startups
      • Wall Street
    • Markets
      • Bonds
      • Commodities & Futures
      • Currencies
      • Funds & ETFs
      • Stocks
    • Crypto
      • Alticoins News
      • Binance News
      • Bitcoins News
      • Blockchain News
      • Ethereum News
      • Token Sales News
      • XRP News
    • Technology
      • Artificial Intelligence
      • Big Data
      • Cloud Computing
      • Cybersecurity
      • Gaming
      • Internet of Things
      • Mobile
      • Social Media
      • Transportation
      • VR & AR
    • FinTech
    • Personal finance
    • Grides
      • Crypto
      • FinTech
      • Investing
      • Personal Finance Guides
      • Techonology
    • Tools
      • Coins
      • ICO List
      • Organigations
      • Events
    Cryptonounce.com
    Home » Zyxel Issues Critical Security Patches for Firewall and VPN Products
    Cybersecurity

    Zyxel Issues Critical Security Patches for Firewall and VPN Products

    AdmincryptBy AdmincryptMay 25, 2023No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    May 25, 2023Ravie LakshmananNetwork Security / Vulnerability

    Zyxel

    Zyxel has released software updates to address two critical security flaws affecting select firewall and VPN products that could be abused by remote attackers to achieve code execution.

    Both the flaws – CVE-2023-33009 and CVE-2023-33010 – are buffer overflow vulnerabilities and are rated 9.8 out of 10 on the CVSS scoring system.

    A brief description of the two issues is below –

    • CVE-2023-33009 – A buffer overflow vulnerability in the notification function that could enable an unauthenticated attacker to cause a denial-of-service (DoS) condition and remote code execution.
    • CVE-2023-33010 – A buffer overflow vulnerability in the ID processing function that could enable an unauthenticated attacker to cause a denial-of-service (DoS) condition and remote code execution.

    The following devices are impacted –

    • ATP (versions ZLD V4.32 to V5.36 Patch 1, patched in ZLD V5.36 Patch 2)
    • USG FLEX (versions ZLD V4.50 to V5.36 Patch 1, patched in ZLD V5.36 Patch 2)
    • USG FLEX50(W) / USG20(W)-VPN (versions ZLD V4.25 to V5.36 Patch 1, patched in ZLD V5.36 Patch 2)
    • VPN (versions ZLD V4.30 to V5.36 Patch 1, patched in ZLD V5.36 Patch 2), and
    • ZyWALL/USG (versions ZLD V4.25 to V4.73 Patch 1, patched in ZLD V4.73 Patch 2)

    Security researchers from TRAPA Security and STAR Labs SG have been credited with discovering and reporting the flaws.

    UPCOMING WEBINAR

    Zero Trust + Deception: Learn How to Outsmart Attackers!

    Discover how Deception can detect advanced threats, stop lateral movement, and enhance your Zero Trust strategy. Join our insightful webinar!

    Save My Seat!

    The advisory comes less than a month after Zyxel shipped fixes for another critical security flaw in its firewall devices that could be exploited to achieve remote code execution on affected systems.

    The issue, tracked as CVE-2023-28771 (CVSS score: 9.8), was also credited to TRAPA Security, with the networking equipment maker blaming it on improper error message handling. It has since come under active exploitation by threat actors associated with the Mirai botnet.

    Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
    Previous ArticleThe Points Guy Names the No. 1 Airline in the U.S.
    Next Article EIA reports a slightly smaller than expected rise in U.S. natural-gas supplies
    Admincrypt
    • Website

    Related Posts

    Microsoft to Pay $20 Million Penalty for Illegally Collecting Kids’ Data on Xbox

    June 7, 2023

    The Role of the Ransomware Negotiator

    June 7, 2023

    New PowerDrop Malware Targeting U.S. Aerospace Industry

    June 7, 2023

    New Malware Campaign Leveraging Satacom Downloader to Steal Cryptocurrency

    June 6, 2023

    Leave A Reply Cancel Reply

    Our Picks
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    FinTech

    NEXT Insurance and Gusto Expand Partnership to Modernize Embedded Payroll Experience

    By AdmincryptJune 7, 20230

    NEXT Insurance, a leading digital insurtech transforming small business insurance, today announced its expanded partnership…

    Business will be able to accept IDs in Apple Wallet with iOS 17, among other changes

    June 7, 2023

    Fable 4 is crucial to Xbox’s future, but it could be a Monkey’s Paw moment for fans

    June 7, 2023

    The Hanover gets Commonwealth Re cat bond at 20% upsized $150m

    June 7, 2023

    Subscribe to Updates

    Get the latest creative news from CRYPTO NOUNCE.

    NEWS
    • Business
    • Crypto
    • Blockchain
    • Markets
    • Technology
    FEATURED SECTIONS
    • Coins
    • ICO List
    • Organigations
    • Events
    • Grides
    FEATURED LINKS
    • Story of the day
    • Videos
    • Infographics
    CONNECT WITH US
    • Facebook
    • Twitter
    • Telegram
    • LinkedIn
    • Pinterest
    ABOUT US
    • Contact
    • Advertise
    • Sitemap
    Copyright © 2023 Cryptonounce All rights reserved. Cryptonounce.
    • Home
    • Buy Now

    Type above and press Enter to search. Press Esc to cancel.

    Sign In or Register

    Welcome Back!

    Login to your account below.

    Lost password?