ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

US Adds 17 Exploited Bugs to “Must Patch” List

criticalVulnerability exploited in the wildimportance 60CVE-2021-32648CVE-2021-35247

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-32648
Authentication Bypass in October CMS Password Reset Enables Account Takeover

October CMS, a content management system built on the Laravel PHP framework, contains an improper authentication flaw (CWE-287) in its october/system package: an attacker can initiate a password reset for any account and then submit a specially crafted request that bypasses the reset-code check, gaining access to that account without knowing the current password. The flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1: 9.1, critical), and takeover of a back-end administrator account would grant the attacker full control of the CMS's content, users, and configuration. Any October CMS deployment running october/system versions prior to Build 472 or v1.1.5 is affected. Exploitation is confirmed in the wild: CISA added CVE-2021-32648 to its Known Exploited Vulnerabilities Catalog on 2022-01-18 as part of a batch of 17 added flaws, requiring patching per vendor instructions, and EPSS assigns a 90.4% probability of exploitation within 30 days (100th percentile). CISA lists ransomware use as unknown, and no public proof-of-concept exploit is known.

Do: Update October CMS to Build 472 or v1.1.5 (or later) following the vendor's update instructions; because the flaw is in CISA's KEV, patching is required for federal agencies. Organizations that cannot patch immediately should restrict network access to the CMS back end and audit recent password-reset requests, back-end logins, and account modifications for signs of takeover, rotating credentials for any accounts with unexpected resets.

9.190% KEV
  • October CMS (october/system package) All versions prior to Build 472 and prior to v1.1.5; fixed in Build 472 and v1.1.5
large~ tens of thousands of installations (roughly 10,000-50,000 sites per public CMS usage trackers; a subset are internet-exposed) - estimate
CVE-2021-35247
Actively Exploited Input Validation Flaw in SolarWinds Serv-U LDAP Login

CVE-2021-35247 is an improper input validation flaw (CWE-20) in the SolarWinds Serv-U web login screen's LDAP authentication path, where submitted characters are not sufficiently sanitized before being passed to the LDAP server. It is triggered remotely over the network with no privileges or user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), by sending crafted, non-sanitized characters through the login-to-LDAP flow; SolarWinds notes that LDAP servers ignored the improper characters and no downstream effect was detected, and the 5.3 (medium) CVSS score reflects a low integrity impact with no confidentiality or availability impact. An attacker gains the ability to feed unsanitized input into the LDAP authentication process; no confirmed code execution or full compromise is documented for this specific bug, but it is nevertheless on CISA's Known Exploited Vulnerabilities catalog. Affected organizations are those running SolarWinds Serv-U whose web login screen uses LDAP authentication. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2022-01-21, Microsoft warned that threat actors attempted to exploit the Serv-U bug in real-world attacks, and reporting on this flaw surfaced alongside the Log4j (Log4Shell) attack wave targeting SolarWinds products.

Do: Schedule an upgrade to the latest SolarWinds Serv-U release, which adds the required input validation and sanitization to the LDAP login path; this is the CISA KEV required action, so KEV deadlines apply. Until patched, restrict access to the Serv-U web login from untrusted networks and review LDAP/authentication logs for suspicious or malformed login input. While updating, also confirm Serv-U is patched for the related critical Serv-U 15.5 root code execution flaws and any Log4j exposure covered in the same reporting cycle.

5.33% KEV
  • SolarWinds Serv-U
moderate≈ several thousand internet-exposed Serv-U servers (estimate; no scan counts in source data)
Full article326 words · extracted from infosecurity-magazine.com · click to collapse

A US government’s security agency has added 17 vulnerabilities currently being actively exploited in the wild to a database of bugs that federal agencies must fix.

The Known Exploited Vulnerabilities Catalog was launched in November last year as part of Binding Operational Directive (BOD) 22-01, designed to make civilian federal government agencies more cyber-resilient.

An initial list of just over 300 CVEs, some of which dated as far back as 2010, has been steadily added to since. The latest update includes vulnerabilities that could be exploited for various ends, including denial of service, privilege escalation, authentication bypass and information disclosure.

Attackers are using them to steal information and credentials, execute malware, access networks and more.

Among the most interesting are CVE-2021-32648, which came to light last week and is an improper authentication flaw in the October CMS. It was exploited in a wide-ranging campaign to hijack and deface Ukrainian government websites.

Another is CVE-2021-35247, listed as an improper input validation vulnerability in SolarWinds Serv-U file servers.

Microsoft researchers discovered it being exploited in Log4j attacks in an attempt to compromise Windows domain controllers. Such attacks failed because Windows domain controllers aren’t vulnerable to Log4Shell.

However, it must be patched by February 4, according to the order from the Cybersecurity and Infrastructure Security Agency (CISA).

There’s an even tighter time frame for CVE-2021-32648 and eight other CVEs listed: these must be fixed by February 1. The remaining seven bugs must be patched by July, according to the update.

While the BOD to patch any vulnerabilities added to the database is only mandatory for civilian federal agencies, the government wants other organizations to follow the same rules.

“While this directive applies to federal civilian agencies, we know that organizations across the country, including critical infrastructure entities, are targeted using these same vulnerabilities,” it said back in November.

“It is therefore critical that every organization adopt this directive and prioritize mitigation of vulnerabilities listed in CISA’s public catalog.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/us-adds-17-exploited-bugs-to-must/