By Interestana AI Editorial — AI-drafted, human-overseen. How we report
CISA Orders Feds to Patch Zyxel Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive on March 19, 2024, mandating federal agencies to patch a critical vulnerability affecting Zyxel GS1900 series network switches. This directive, identified as Directive Number 24-01, stems from the active exploitation of this flaw by malicious actors who have been observed stealing data from compromised systems. The vulnerability, designated CVE-2023-28771, allows unauthenticated attackers to execute arbitrary code on the affected devices, enabling them to gain unauthorized access and exfiltrate sensitive information. CISA has classified this vulnerability as critical, emphasizing the immediate threat it poses to federal networks. The agency requires all federal civilian executive branch (FCEB) agencies to implement mitigation measures by April 2, 2024. This includes applying vendor-supplied patches or implementing approved workarounds to secure their networks. Failure to comply with the directive by the deadline will necessitate a formal exception request. The Zyxel GS1900 series consists of unmanaged and smart managed switches commonly used in enterprise and small to medium-sized business environments. These devices are integral to network infrastructure, managing traffic flow and connecting various endpoints. The exploitation of CVE-2023-28771 highlights a significant risk to organizations relying on these switches, as attackers can leverage the vulnerability to establish a persistent presence within a network, conduct further reconnaissance, and launch more sophisticated attacks. CISA's directive underscores the agency's commitment to protecting federal information systems from emerging cyber threats. The agency continuously monitors the threat landscape and issues directives to ensure agencies maintain a strong security posture. This specific directive is a proactive measure to prevent widespread compromise and data breaches within the federal government. The urgency of the directive is further amplified by the fact that the vulnerability has already been exploited in the wild, meaning attackers are actively targeting these devices. Federal agencies are advised to consult Zyxel's official advisories and security updates for the latest information on patches and mitigation strategies. The directive also encourages agencies to report any suspicious activity or incidents related to this vulnerability to CISA. The scope of the directive applies to all Zyxel GS1900 series switches deployed within FCEB agencies, regardless of their configuration or operational status. Agencies are responsible for inventorying their assets and ensuring all vulnerable devices are addressed within the stipulated timeframe. This incident serves as a stark reminder of the importance of timely vulnerability management and patching, especially for network infrastructure devices that form the backbone of an organization's digital operations. The active exploitation of CVE-2023-28771 by threat actors demonstrates a clear and present danger that requires immediate attention and remediation efforts from all affected federal agencies.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.