April 16, 2014 – Anaheim, CA – Zyxel Communications, a leading provider of secure broadband networking, Internet access, connected home and routing products, today reported that Zyxel products ranging from business products to DSL CPEs are not affected by the Heartbleed OpenSSL vulnerability.
The company has carried out extensive checks and confirmed that the OpenSSL versions used in Zyxel business solutions and DSL CPE products are not at risk.
Zyxel business solutions including security appliances, Gateways, Switches and WLAN AP/ Controllers, use OpenSSL, but not the affected versions. This means all firewalls and firmware versions remain secure from the Heardbleed vulnerability, which was found in OpenSSL versions 1.0.1f and 1.0.2-beta1.
The same applies to Zyxel DSL CPE products, and other models that support HTTPs Remote Management. The OpenSSL versions these products use are not affected by the Heartbleed bug.
To improve business network security, Zyxel strongly recommends that users add our Intrusion Detection and Prevention (IDP) service to USG (Unified Security Gateway) to protect business from such threats. The Zyxel USG series effectively guards servers in business networks from break-in via the Heartbleed bug. To further enhance protection, the Zyxel USG series featuring the IDP will automatically connect to Zyxel Security Distribution Network (ZSDN) to retrieve the latest updates. A new IDP signature has already been released. Zyxel UTM customers can get more information on licensing IDP, Anti-Virus and Content Filtering subscription services to better protect their networks against Heartbeat and other cyber threats.
Heartbleed is a vulnerability in the OpenSSL implementation that can be exploited by hackers to steal information stored in the memory of Web servers. The Web server memory could potentially have sensitive information including login credentials and cookies info that may be exploitable by hackers. Here is a link to an informative article on Heartbleed
About Zyxel Communications
Zyxel, a pioneer in IP technology for over two decades, provides a complete portfolio of multi-service LTE, fiber and DSL broadband gateways, home connectivity solutions, smart home devices and enterprise-class Ethernet switches, security and Wi-Fi equipment for small to mid-size business. ZyXEL offers integrated, interoperable network solutions based on open standards. Headquartered in Anaheim, California, Zyxel offers its partners service-rich solutions backed by a domestic team of logistic, sales, and technical support professionals.
Zyxel Communications, Inc. - North America Headquarters
Tel: +1 714 632 0882 x276