ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

US Government Has Three Weeks to Patch Cyclops Blink Bug

highRansomware exploited in the wildimportance 60CVE-2022-23176

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-23176
Privilege Escalation in WatchGuard Firebox/XTM Fireware OS

WatchGuard Firebox and XTM appliances running affected versions of Fireware OS contain a privilege escalation flaw that allows a remote attacker who already holds unprivileged credentials to obtain a privileged management session via exposed management access. The flaw is triggered when management access is exposed (for example, to the internet) and an attacker authenticates with low-privileged credentials, at which point they can elevate to privileged management of the appliance. Because the CVSS v3.1 score of 8.8 carries high confidentiality, integrity, and availability impact, full compromise of the appliance is the realistic outcome. Organizations running Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, or 12.2.x through 12.5.x before 12.5.7_U3 are affected. The vulnerability is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-04-11, and the Russia-linked Cyclops Blink botnet used it as an initial access vector to infect thousands of devices before the FBI disrupted the botnet.

Do: Upgrade affected Fireware OS branches to 12.7.2_U1, 12.1.3_U3, or 12.5.7_U3 (or later) per WatchGuard's instructions, as required by CISA's KEV catalog. Until patched, restrict appliance management access to trusted networks or management VPNs rather than exposing it to the internet. Because this flaw was used to deploy the Cyclops Blink botnet, administrators should also check Firebox/XTM devices for signs of that compromise using vendor detection guidance.

8.813% KEV
  • WatchGuard Firebox and XTM appliances (Fireware OS) Fireware OS before 12.7.2_U1; 12.x before 12.1.3_U3; 12.2.x through 12.5.x before 12.5.7_U3
masson the order of 100,000+ potentially exposed Firebox/XTM appliances (WatchGuard's installed base is cited in the millions, with management access commonly…
Full article297 words · extracted from infosecurity-magazine.com · click to collapse

A leading US cybersecurity agency has ordered civilian federal government entities to urgently patch a bug being exploited by Russian state hackers.

The high severity privilege escalation vulnerability CVE-2022-23176 affects WatchGuard Firebox and XTM appliances. It has now been added to the Known Exploited Vulnerabilities Catalog maintained by the US Cybersecurity and Infrastructure Security Agency (CISA).

According to NIST, it allows a “remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.”

Russia’s notorious Sandworm group has been exploiting the bug as part of its Cyclops Blink campaign to build a large botnet out of compromised home office WatchGuard and Asus router devices.

The malware itself has been described as “sophisticated and modular,” meaning new functionality could be added at any time. It’s deployed as part of a firmware ‘update’ to achieve persistence when an infected device is rebooted and make remediation harder.

It’s not known to what ends the botnet has been put, although some have suggested it may have been used to support DDoS attacks against Ukrainian entities. However, it was deemed dangerous enough for the US authorities to intervene recently.

A special DoJ operation saw court orders issued to enable investigators to “copy and remove” the malware from infected devices used for command and control (C&C).

Officers also closed the ports Sandworm was using to remotely manage the infected C&C devices. However, the FBI warned that any devices previously attacked may still be vulnerable to exploitation unless owners follow vendor advice on remediation.

That’s where patching CVE-2022-23176 comes in.

Although the CISA catalog applies only to federal agencies, it urges all organizations to follow the list as a best practice measure to improve cyber-hygiene.

Civilian federal agencies now have until May 2 to patch the flaw.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/us-government-patch-cylops-blink/