Attacks on SolarWinds Servers Also Linked To Chinese Threat Actor
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-10148 | Authentication Bypass in SolarWinds Orion API (CVE-2020-10148) The SolarWinds Orion API contains a critical authentication bypass (CWE-288/CWE-306, CVSS 9.8) that allows a remote, unauthenticated attacker to execute API commands on the Orion Platform. It is triggered by specially crafted requests to the Orion API that reach endpoints with authorization skipped, requiring no privileges or user interaction. By issuing these API commands, an attacker can take control of the SolarWinds instance; in observed intrusions, the flaw was used to install the SUPERNOVA webshell on Orion servers. Any organization running Orion Platform 2019.4 HF 5, 2020.2 with no hotfix installed, or 2020.2 HF 1 is affected. Exploitation is in the wild: the flaw is listed in CISA's KEV (added 2021-11-03), has been linked to the China-nexus actor DEV-0322 per public reporting, and EPSS assigns it a 92% probability of exploitation within 30 days. Do: Apply the Orion Platform updates/hotfixes per SolarWinds' instructions and move all installations off the affected builds (2019.4 HF 5, 2020.2 without hotfix, 2020.2 HF 1). Until patched, restrict access to the Orion web console and API to trusted networks only. Hunt for compromise by checking for the SUPERNOVA webshell in the Orion web root and reviewing API logs for unauthenticated API command execution. | 9.8 | 92% | KEV |
| largetens of thousands of Orion deployments (roughly 25,000-33,000 customer sites) |
Full article327 words · extracted from therecord.media · click to collapse
Back in December 2020, days after the massive SolarWinds supply chain attack came to light, Microsoft warned about a second threat actor targeting SolarWinds Orion servers installed on customer premises, independently from the supply chain compromise. This second group's attacks did not rely on compromising the SolarWinds app update infrastructure but instead exploited an authentication bypass vulnerability (CVE-2020-10148) in the SolarWinds Orion API to install web shells on companies Orion servers. The web shell, codenamed SUPERNOVA, acted as a backdoor on Orion IT monitoring platforms, allowing threat actors to access and steal data from companies' internal networks. Reports published at the time by the Cybersecurity and Infrastructure Security Agency, Palo Alto Networks, and Guidepoint Security did not formally link this malware to the threat group behind the SolarWinds supply chain attack —which the US government formally linked to Russia— and described any exploitation as taking place in parallel with the broader and much more intrusive supply chain attack. But in a report published today, cybersecurity firm Secureworks said it found links between the SUPERNOVA malware and attacks carried out last year in August against Zoho ManageEngine servers, using a zero-day published on Twitter. Secureworks said it's tracking this threat actor under the codename of Spiral and that "characteristics of the activity suggest the group is based in China." "Similarities between SUPERNOVA-related activity in November [against Orion servers] and activity that CTU researchers analyzed in August [against Zoho servers] suggest that the SPIRAL threat group was responsible for both intrusions," Secureworks said today. "Characteristics of these intrusions indicate a possible connection to China." But what Secureworks did not specifically point out was if the Spiral group has any affiliations with Chinese government-backed cyber operations or if the group is just your regular run-of-the-mill cybercrime outfit looking to sell access, plunder, or ransom corporate environments. A Secureworks spokesperson did not respond to a request for comment.Secureworks solves SUPERNOVA mystery
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/attacks-on-solarwinds-servers-also-linked-to-chinese-threat-actor