Skip to content
COOEY

EXPOSURES › CVE-2024-11667

CVE-2024-11667

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-12-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-11667 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

Zyxel firewalls had a path traversal flaw in their web management interface that allowed attackers to upload or download files via crafted URLs.

This path traversal vulnerability in Zyxel firewalls allowed attackers to manipulate URLs to upload or download files, potentially leading to unauthorized access or malware deployment. DIB organizations must ensure all network hardware is patched against known CVEs, as unpatched flaws in critical infrastructure like firewalls can be exploited in the wild to compromise network perimeters. Immediate action includes verifying patch levels on all Zyxel devices and monitoring for signs of unauthorized file manipulation.

Shame score — A critical path traversal flaw in widely deployed firewalls was actively exploited in the wild and linked to ransomware, indicating severe negligence in patch management and security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.