ZeroHour

CVE-2023-41266

KEV ransomwaremoderate

Unauthenticated Path Traversal in Qlik Sense Enterprise for Windows

CISA: Qlik Sense Path Traversal Vulnerability

CVSS 3.1
6.5 medium
EPSS
85%p100
Published
()
KEV added
AI analysis

CVE-2023-41266 is a path traversal vulnerability (CWE-22) in Qlik Sense Enterprise for Windows that allows an unauthenticated remote attacker to generate an anonymous session. By sending crafted HTTP requests over the network, an attacker with no credentials can use that anonymous session to transmit requests to otherwise unauthorized endpoints (CVSS 3.1: 6.5). In documented campaigns, this access has been leveraged as an entry point for Cactus ransomware attacks against Qlik Sense deployments, and related reporting describes follow-on custom Linux malware delivery. Any organization running Qlik Sense Enterprise for Windows on the affected release tracks listed below is exposed, particularly when the server is internet-facing. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-12-07 with ransomware use flagged as known, and EPSS assigns an 84.8% probability of exploitation within 30 days.

What to do: Upgrade to August 2023 IR, or to the first fixed patch on your release track: May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13. Because ransomware exploitation is confirmed, prioritize patching any internet-exposed Qlik Sense servers and review logs for anonymous sessions and HTTP requests to unauthorized endpoints. Hunt for signs of Cactus ransomware activity on hosts that had the vulnerable version exposed.

Affected
Qlik Sense Enterprise for WindowsMay 2023 Patch 3 and earlier; February 2023 Patch 7 and earlier; November 2022 Patch 10 and earlier; August 2022 Patch 12 and earlier (fixed in August 2023 IR,
Estimated exposure
moderate≈2,000–3,000 internet-exposed Qlik Sense Enterprise for Windows servers (order of magnitude ~10^3); total on-prem deployments likely higher — Public internet scan data around the disclosure period showed on the order of a few thousand Qlik Sense servers exposed to the internet; the full on-prem install base across enterprise deployments is not published and is likely larger, but…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

CISA Known Exploited Vulnerability
Affected
Qlik Sense
Required action
Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
qlik
Products
qlik sense
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news