Shimo VPN service contains six unpatched vulnerabilities, Talos discovers
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-4007 +1 in the same advisory: …4004 | An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig functionality. An exploitable privilege escalation vulnerability exists in the Shimo VPN 4.1.5.1 helper service in the deleteConfig functionality. The program is able to delete any protected file on the system. An attacker would need local access to the machine to successfully exploit the bug. NVD description · AI analysis pending | 7.1 group max | <1% | PoC |
| — |
Full article711 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Details of the vulnerabilities were released after Cisco made “repeated attempts” to communicate with Shimo over 90 days to no avail, Talos said.
A series of vulnerabilities in virtual private network service Shimo’s Helper Tool, a popular app used to connect multiple VPNs for Mac operating systems, would make it possible for hackers to obtain root control, according to research published Monday by Cisco’s Talos research team.
Researchers detailed six vulnerabilities in the Shimo VPN Helper Tool that relies on to carry out its privileged work, according to a blog post. Details of the vulnerabilities were released after Cisco made “repeated attempts” to communicate with Shimo over 90 days to no avail, Talos said.
Shimo did not immediately respond to a request for comment from CyberScoop.
One vulnerability, listed as CVE-2018-4004, is a privilege escalation vulnerability that resides in the Shimo VPN helper’s disconnectService function, and would allow a “non-root user to kill privileged processes on the system.” Another, CVE-2018-4007, resides in the deleteConfig functionality and “could allow an attacker to delete any protected file on the system.” Shimo VPN version 4.1.5.1 is known to be vulnerable, according to Cisco.
All of the vulnerabilities listed require an attacker to have local access to a device. A complete list of vulnerabilities and technical details is available on Cisco’s Talos blog.
This disclosure comes after the U.S. Department of Homeland Security on Friday alerted the public to a flaw in multiple enterprise VPN apps that could give hackers access to other apps running on a VPN connection, as CyberScoop reported. The issue involves insecure cookie storage in memory or log files. DHS said the vulnerability was present in apps made by Cisco, F5 Networks, Palo Alto Networks and Pulse Secure, though Carnegie Mellon University’s CERT Coordination Center said other VPN apps likely were affected.
Users rely on VPNs to protect their location and shield their internet activity at times when they might be especially vulnerable. Hackers, by breaching VPNs, can exploit the trust users place in VPNs for their own gain, either to steal business secrets, conduct espionage or for other purposes.
Shimo is advertised as the “Fort Knox of VPNs” in part because the company follows the “highest security standards,” according to its website.
More Scoops
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
In a letter first reported by CyberScoop, Ron Wyden, D-Ore., said ‘devastating’ attacks on the federal government have accumulated due to the tech.
Treasury sanctions First VPN Service, others for abetting ransomware gangs
European authorities take down prolific cybercrime VPN service
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/shimo-vpn-vulnerabilities-cisco-talos/