Critical ManageEngine RCE flaw is being exploited (CVE-2022-35405)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-35405 | Deserialization RCE in ManageEngine Password Manager Pro, PAM360, and Access Manager Plus Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain a flaw classified as deserialization of untrusted data (CWE-502) that allows an unauthenticated attacker to achieve remote code execution by sending crafted serialized data to the server. Because no authentication or user interaction is required, any client that can reach the product's network service can submit input that the application deserializes and executes. A successful attacker gains code execution with the privileges of the product's service, typically yielding control of the server and, critically, access to the vault of privileged credentials these products store, enabling lateral movement and ransomware campaigns. Any organization running one of these three ManageEngine password and access management products is in scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-22, and EPSS estimates a 99.9% probability of exploitation within 30 days. Do: Apply the updates Zoho released for all three products immediately, as CISA's required action specifies applying vendor updates: inventory whether you run Password Manager Pro, PAM360, or Access Manager Plus, and upgrade to the fixed builds named in each product's advisory. Until patched, restrict network access to the products' HTTPS management service (e.g., Password Manager Pro's default service port 7272) to trusted administrative networks only. After patching, hunt for signs of compromise such as unexpected processes, new accounts, or use of vaulted credentials, since the KEV listing implies exploitation and ransomware association is listed as unknown. | 9.8 | 100% | KEV PoC |
| largetens of thousands of enterprise deployments across the three products, including several thousand internet-exposed instances visible in public scans,… |
Full article352 words · extracted from helpnetsecurity.com · click to collapse
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2022-35405, a critical remote code execution vulnerability in ManageEngine PAM360, Password Manager Pro, and Access Manager Plus, to its Known Exploited Vulnerabilities (KEV) Catalog.
The details of in-the-wild exploitation of the flaw aren’t available – though, according to data collected by Greynoise, exploitation attempts don’t seem widespread.
About CVE-2022-35405
CVE-2022-35405 is a remote code execution vulnerability that can be exploited to execute arbitrary code on affected installations of Password Manager Pro and PAM360 without prior authentication, and on Access Manager Plus with prior authentication.
It affects:
- Password Manager Pro versions 12100 and below
- PAM360 versions 5500 and below
- Access Manager Plus versions 4302 and below
Fixes for the vulnerability were released in late June. “We have fixed this vulnerability by completely removing the vulnerable components from PAM360 and Access Manager Plus, and by removing the vulnerable parser from Password Manager Pro,” ManageEngine stated in the advisory, and urged administrators to upgrade to a fixed version, as a proof-of-concept exploit was already public.
Since then, other PoCs have been released – including one by Vinicius Pereira, the researcher who flagged it in the first place – and a Metasploit module.
More details about the vulnerability can be found in Pereira’s blog post.
Attack prevention
The vulnerability can be easily exploited and, depending on the targeted application, without requiring attackers to be authenticated and without the need for user interaction.
Under Binding Operational Directive (BOD) 22-01, all US federal civilian executive branch agencies are required to remediate vulnerabilities in the KEV catalog within specific timeframes.
But “CISA strongly recommends all organizations review and monitor the KEV catalog and prioritize remediation of the listed vulnerabilities to reduce the likelihood of compromise by known threat actors.”
Vulnerabilities in ManageEngine applications are often taken advantage of by attackers.
If they haven’t already, enterprise admins should upgrade their solutions to a fixed version. ManageEngine advises those whose machine has been compromised to disconnect and isolate it, and to create a zip file containing application logs and send them to the company’s support team.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/09/23/cve-2022-35405-exploited/