ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Hackers backdoored Cisco ASA devices via two zero-days (CVE-2024-20353, CVE-2024-20359)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-20353
+1 in the same advisory: …20359
Unauthenticated Device-Reload DoS in Cisco ASA and FTD Web Servers

CVE-2024-20353 is a denial-of-service flaw in the management and VPN web servers of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software, caused by incomplete error checking when parsing an HTTP header (tracked as CWE-835, a loop-exit defect). An unauthenticated, remote attacker can trigger it by sending a crafted HTTP request to the device's web server, causing the firewall/VPN appliance to reload unexpectedly. A successful exploit yields no data theft from the flaw itself but takes the device offline, and repeated requests can sustain an outage of the edge firewall and VPN service. Any organization running ASA or FTD with these web servers reachable by attackers is exposed, which includes nearly every internet-facing Cisco edge deployment. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-24, is referenced in a public Cisco Talos writeup on the ArcaneDoor campaign, where suspected state-sponsored (China-linked) actors chained it with CVE-2024-20359 to backdoor ASA perimeter devices, and EPSS assigns it a 70.7% probability of exploitation within 30 days (99th percentile).

Do: Upgrade ASA and FTD to the fixed releases listed in Cisco's security advisory (version ranges not included in this data), and because attackers in the ArcaneDoor campaign may have persisted on devices via the related CVE-2024-20359 backdoor, check for unexpected configuration changes or persistence before and after patching. Restrict exposure of the ASA/FTD management and VPN web servers to trusted source addresses while remediation is pending. Per CISA's KEV required action, apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

8.6
group max
71% KEV PoC
  • Cisco Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
massseveral hundred thousand internet-exposed Cisco ASA/FTD appliances worldwide
CVE-2024-20358
A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense

A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This vulnerability exists because the contents of a backup file are improperly sanitized at restore time. An attacker could exploit this vulnerability by restoring a crafted backup file to an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system as root.

NVD description · AI analysis pending
6.7<1%
  • cisco adaptive security appliance software
  • cisco secure firewall threat defense
Full article692 words · extracted from helpnetsecurity.com · click to collapse

A state-sponsored threat actor has managed to compromise Cisco Adaptive Security Appliances (ASA) used on government networks across the globe and use two zero-day vulnerabilities (CVE-2024-20353, CVE-2024-20359) to install backdoors on them, Cisco Talos researchers have shared on Wednesday.

CVE-2024-20353 CVE-2024-20359

First confirmed activity observed by a Cisco customer dates to early January 2024 but the actual attacks started in November 2023. “Further, we have identified evidence that suggests this capability was being tested and developed as early as July 2023,” the researchers added.

The custom malware

The initial access vector in this campaign – dubbed ArcaneDoor – is still unknown.

The threat actor, which Cisco Talos tracks as UAT4356 and Microsoft as STORM-1849, used custom malware:

  • Line Dancer, a shellcode interpreter that resides only in memory, to upload and execute arbitrary shellcode payloads
  • Line Runner, a backdoor to maintain persistence.

“On a compromised ASA, the attackers submit shellcode via the host-scan-reply field, which is then parsed by the Line Dancer implant. The host-scan-reply field, typically used in later parts of the SSL VPN session establishment process, is processed by ASA devices configured for SSL VPN, IPsec IKEv2 VPN with ‘client-services’ or HTTPS management access,” the researchers explained.

“The actor overrides the pointer to the default host-scan-reply code to instead point to the Line Dancer shellcode interpreter. This allows the actor to use POST requests to interact with the device without having to authenticate and interact directly through any traditional management interfaces.”

Line Dancer has been used to disable syslog (the logging protocol), exfiltrate the command show configuration and packet captures, execute CLI commands, force the device to skip creating a crash dump when it crashes (to stymie forensic analysis), and create ways to always be able to remotely connect to the device.

Line Runner exploits functionality related to a legacy ASA capability to find a specific LUA file, unzip it, execute it and delete it. The scripts contained in it allowed the threat actor to maintain a HTTP-based Lua backdoor on the device that will persist despite reboots and upgrades.

Patch, investigate, respond

Cisco has released patches for CVE-2024-20353 and CVE-2024-20359, provided indicators of compromise, Snort signatures, and has outlined several methods for locating the Line Runner backdoor on ASA devices.

Organizations using Cisco ASA are advised to implement the patches as soon as possible as there are no workarounds that can address the two vulnerabilities.

“Customers are also strongly encouraged to monitor system logs for indicators of undocumented configuration changes, unscheduled reboots, and any anomalous credential activity,” Cisco advised.

Cisco has also released patches for a third vulnerability (CVE-2024-20358) affecting Cisco ASAs, which is not being exploited by these attackers.

Targeted attacks

Cisco researchers worked on analyzing these attacks with the help of several companies (Microsoft, Lumen Technologies) and governmental cybersecurity agencies from the US, Canada, Australia and the UK.

“This actor utilized bespoke tooling that demonstrated a clear focus on espionage and an in-depth knowledge of the devices that they targeted, hallmarks of a sophisticated state-sponsored actor,” the researchers noted.

The sophisticated anti-forensic measures employed, the use of zero-days, and the focus on specific targets only reinforced that conclusion.

ArcaneDoor is the latest in a series of campaigns aimed at compromising “edge” networking devices such as VPNs and firewalls, most of which have been attributed to Chinese state-sponsored hackers.

“Further, network telemetry and information from intelligence partners indicate the actor is interested in — and potentially attacking — network devices from Microsoft and other vendors. Regardless of your network equipment provider, now is the time to ensure that the devices are properly patched, logging to a central, secure location, and configured to have strong, multi-factor authentication (MFA),” Cisco Talos warned.

“Gaining a foothold on these devices allows an actor to directly pivot into an organization, reroute or modify traffic and monitor network communications.”

UPDATE (April 25, 2024, 06:10 a.m. ET):

The recently released Coalition 2024 Cyber Claims Report says businesses with internet-exposed Cisco ASA devices were nearly five times more likely to experience a cyber insurance claim in 2023.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/04/24/cve-2024-20353-cve-2024-20359/