A critical security flaw in widely used Zyxel network switches has been confirmed as actively exploited, leading the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to issue an emergency directive ordering federal agencies to apply patches within days.

The directive, issued Friday, targets the Zyxel GS1900 series of unmanaged switches. Agencies must either disconnect the affected devices or patch them by Thursday, September 26, according to a report from BleepingComputer. The urgency stems from confirmed attacks in the wild where threat actors are leveraging the flaw for data theft and to establish persistent network access.

The vulnerability, assigned CVE-2024-23309 and rated high-severity with a CVSS score of 7.5, resides in the management interface. It allows an unauthenticated remote attacker to access sensitive information and alter device configurations.

While CISA's mandate applies specifically to U.S. federal civilian agencies, the threat is global. Organizations of all sizes should consider this a directive to audit their own infrastructure, as the affected switches are common in small-to-medium business and branch office environments.

The incident highlights a persistent security blind spot. Foundational network hardware like these switches often lacks the rigorous patch management applied to servers or firewalls. This "set-and-forget" mentality can leave critical devices vulnerable, providing attackers with a stealthy foothold to intercept traffic or pivot across a network.

For any organization using Zyxel GS1900 switches, the recommended course of action is immediate: * Audit: Identify all instances of the affected switch models in the network inventory. * Patch: Download and apply the latest firmware update from Zyxel's support portal without delay. * Isolate: If immediate patching isn't possible, restrict access to the switch's management interface from untrusted networks. * Monitor: Review logs for suspicious activity targeting switch management.

This coordinated response from a major national cybersecurity agency underscores that the risk is active and demands prompt attention from network administrators worldwide.


廣泛使用的合勤網絡交換機中一個關鍵安全漏洞已被證實遭積極利用,導致美國網絡安全和基礎設施安全局(CISA)發布緊急指令,命令聯邦機構在數日內安裝補丁。

據 BleepingComputer 報導,這項於星期五發出的指令針對合勤 GS1900 系列非管理型交換機。相關機構必須在 9 月 26 日星期四前,隔離受影響設備或為其安裝補丁。其緊迫性源於已確認的實際攻擊事件,威脅行為者正利用該漏洞進行數據竊取,並建立持久性網絡訪問權限。

被評定為高風險、CVSS 評分為 7.5 的漏洞編號 CVE-2024-23309,存在於管理介面中。它允許未經身份驗證的遠端攻擊者訪問敏感信息並更改設備配置。

雖然 CISA 的命令專門適用於美國聯邦民事機構,但此威脅具有全球性。各類組織均應將此視為對自身基礎設施進行審計的指引,因為受影響的交換機在中小型企業及分支機構環境中十分常見。

此次事件突顯了一個持續存在的安全盲點。這類基礎網絡硬件(如交換機)通常缺乏應用於伺服器或防火牆的嚴格補丁管理。這種「設定後即忘」的心態可能使關鍵設備暴露於風險中,為攻擊者提供隱蔽的立足點,以攔截流量或在橫向移動網絡。

對於任何使用合勤 GS1900 交換機的組織,建議立即採取以下行動: * 審計: 識別網絡庫存中所有受影響的交換機型號。 * 補丁: 毫不延遲地從合勤支援門戶下載並應用最新的韌體更新。 * 隔離: 若無法立即安裝補丁,請限制不受信任網絡對交換機管理介面的訪問。 * 監控: 檢查日誌,留意針對交換機管理的可疑活動。

這次來自主要國家網絡安全機構的協調應對,突顯了風險的現時性與全球網絡管理員迅速關注的必要性。

新聞來源 / Original News Source