{"id":150054,"date":"2022-05-17T02:39:40","date_gmt":"2022-05-17T04:39:40","guid":{"rendered":"https:\/\/teknomers.com\/fr\/fais-attention-les-pirates-commencent-a-exploiter-la-recente-vulnerabilite-rce-des-pare-feu-zyxel\/"},"modified":"2022-05-17T02:39:52","modified_gmt":"2022-05-17T04:39:52","slug":"fais-attention-les-pirates-commencent-a-exploiter-la-recente-vulnerabilite-rce-des-pare-feu-zyxel","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/fais-attention-les-pirates-commencent-a-exploiter-la-recente-vulnerabilite-rce-des-pare-feu-zyxel\/","title":{"rendered":"Fais attention!  Les pirates commencent \u00e0 exploiter la r\u00e9cente vuln\u00e9rabilit\u00e9 RCE des pare-feu Zyxel"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<p>Lundi, l&#8217;agence am\u00e9ricaine de cybers\u00e9curit\u00e9 et de s\u00e9curit\u00e9 des infrastructures <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/current-activity\/2022\/05\/16\/cisa-adds-two-known-exploited-vulnerabilities-catalog\" target=\"_blank\">ajout\u00e9e<\/a> deux failles de s\u00e9curit\u00e9, dont le bogue d&#8217;ex\u00e9cution de code \u00e0 distance r\u00e9cemment divulgu\u00e9 affectant les pare-feu Zyxel, \u00e0 son <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">Catalogue des vuln\u00e9rabilit\u00e9s exploit\u00e9es connues<\/a>citant des preuves d&#8217;exploitation active.<\/p>\n<p>Suivie sous le nom de CVE-2022-30525, la vuln\u00e9rabilit\u00e9 est class\u00e9e 9,8 pour la gravit\u00e9 et concerne une faille d&#8217;injection de commande dans certaines versions du pare-feu Zyxel qui pourrait permettre \u00e0 un adversaire non authentifi\u00e9 d&#8217;ex\u00e9cuter des commandes arbitraires sur le syst\u00e8me d&#8217;exploitation sous-jacent.<\/p>\n<p>Les appareils concern\u00e9s incluent &#8211;<\/p>\n<ul>\n<li>USG FLEX 100, 100W, 200, 500, 700<\/li>\n<li>USG20-VPN, USG20W-VPN<\/li>\n<li>ATP 100, 200, 500, 700, 800 et<\/li>\n<li>S\u00e9rie VPN<\/li>\n<\/ul>\n<p>Le probl\u00e8me, pour lequel des correctifs ont \u00e9t\u00e9 publi\u00e9s par la firme ta\u00efwanaise fin avril (ZLD V5.30), est devenu public le 12 mai \u00e0 la suite d&#8217;un processus de divulgation coordonn\u00e9 avec Rapid7.<\/p>\n<p>\u00c0 peine un jour plus tard, la Fondation Shadowserver <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/Shadowserver\/status\/1525561213115158529\" target=\"_blank\">mentionn\u00e9<\/a> il a commenc\u00e9 \u00e0 d\u00e9tecter les tentatives d&#8217;exploitation, la plupart des appareils vuln\u00e9rables \u00e9tant situ\u00e9s en France, en Italie, aux \u00c9tats-Unis, en Suisse et en Russie.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/crowdsec-tour-d\" target=\"_blank\" title=\"CyberSecurity\"><\/a><\/div>\n<p>\u00c9galement ajout\u00e9 par CISA au catalogue est <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-22947\" target=\"_blank\">CVE-2022-22947<\/a>une autre vuln\u00e9rabilit\u00e9 d&#8217;injection de code dans Spring Cloud Gateway qui pourrait \u00eatre exploit\u00e9e pour permettre une ex\u00e9cution \u00e0 distance arbitraire sur un h\u00f4te distant au moyen d&#8217;une requ\u00eate sp\u00e9cialement con\u00e7ue.<\/p>\n<p>La vuln\u00e9rabilit\u00e9 est not\u00e9e 10 sur 10 sur le syst\u00e8me de notation des vuln\u00e9rabilit\u00e9s CVSS et a depuis \u00e9t\u00e9 <a rel=\"nofollow noopener\" href=\"https:\/\/tanzu.vmware.com\/security\/cve-2022-22947\" target=\"_blank\">adress\u00e9<\/a> dans Spring Cloud Gateway versions 3.1.1 ou ult\u00e9rieures et 3.0.7 ou ult\u00e9rieures \u00e0 partir de mars 2022.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/05\/watch-out-hackers-begin-exploiting.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lundi, l&#8217;agence am\u00e9ricaine de cybers\u00e9curit\u00e9 et de s\u00e9curit\u00e9 des infrastructures ajout\u00e9e deux failles de s\u00e9curit\u00e9, dont le bogue d&#8217;ex\u00e9cution de code \u00e0 distance r\u00e9cemment divulgu\u00e9 affectant les pare-feu Zyxel, \u00e0 son Catalogue des vuln\u00e9rabilit\u00e9s exploit\u00e9es connuescitant des preuves d&#8217;exploitation active. Suivie sous le nom de CVE-2022-30525, la vuln\u00e9rabilit\u00e9 est class\u00e9e 9,8 pour la gravit\u00e9 et [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":150055,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[2256,11039,4168,4158,4165,4161,133,17566,2728,4157,4159,4171,4170,65,4167,4160,4163,4162,5467,4394,22778,27730,4172,4169,4166,3667,4164,40731],"class_list":["post-150054","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-attention","tag-commencent","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-des","tag-exploiter","tag-fais","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-les","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-parefeu","tag-pirates","tag-rce","tag-recente","tag-securite-informatique","tag-securite-internet","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle","tag-zyxel"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/150054","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=150054"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/150054\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/150055"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=150054"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=150054"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=150054"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}