FLEX H Firmware Boot Issues

Options
m0x7e
m0x7e Posts: 2 image  Freshman Member

There is a security flaw in the current firmware of my device (and most probably other devices of this series).

When the device is rebooted, the configuration on the interfaces is applied and for round about one minute, the configured Firewall rules are not applied.

 

I realized that when rebooting my device with service PING not allowed towards the Device, but the PING went through during bootup.

Even worse is, that for example NAT rules are anyway applied - and then not filtered.

 

In combination with a Denial of Service Attack this will lead to information exposure.

 

Tested Device:

V1.37(ABXF.1) running on USG FLEX 100H.

 

Suggested Remediation: A general Deny ALL must be applied as long as the bootup is not completely finished.

I wrote this first to the security mail address, but they redirected me here. :)

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,739 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @m0x7e

    Thanks for your input. I'm clarifying with our team on it. I will update you once I get further information.

    Zyxel Melen


  • Zyxel_Melen
    Zyxel_Melen Posts: 4,739 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @m0x7e

    We tried to replicate this issue with our configuration and there's no issue as yours. Could you help to provide your configuration for us to investigate it? I have sent you a private message and you may share the configuration in there.

    Zyxel Melen


  • nicolas2ker
    nicolas2ker Posts: 5 image  Freshman Member
    First Comment
    edited April 7

    ===content been moved to the correct post===