H-ISA TLP White Vulnerablilty Bulletin: Critical Zyxel Vulnerability CVE-2023-28771

Summary:

On May 1, 2023, Health-ISAC was made aware of a Zyxel vulnerability that could be used for remote code execution attacks.

Headquartered in Hsinchu, Taiwan, Zyxel is a global networking equipment and solutions provider that offers a wide range of products for businesses and consumers. The company specializes in developing and manufacturing network devices, including switches, routers, firewalls, wireless access points, and network storage devices. Zyxel products are used by small and medium-sized businesses, enterprise organizations, service providers, and home users across all sectors, including healthcare.

Health-ISAC has delivered Targeted Alerts to member organizations known to be leveraging Zyxel appliances for network defense.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272