ZeroHour
The Recordpublished ()ingested

CISA adds seven bugs to Known Exploited Vulnerabilities Catalog

highExploit / PoC exploited in the wildimportance 60CVE-2022-1040CVE-2022-26871

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-1040
Authentication Bypass Leading to Unauthenticated RCE in Sophos Firewall (SFOS)

CVE-2022-1040 is a critical authentication bypass in the User Portal and Webadmin of Sophos Firewall (SFOS) version v18.5 MR3 and older. A remote, unauthenticated attacker who can reach either web-facing service bypasses authentication and executes code on the firewall appliance. Successful exploitation yields full device compromise (CVSS 9.8 with high confidentiality, integrity, and availability impact), enabling traffic interception, persistence, and pivoting into the protected network. Any organization running an affected Sophos Firewall version where the User Portal or Webadmin is reachable, especially from the internet, is exposed. Exploitation is confirmed in the wild: it was exploited as a zero-day in March 2022, added to CISA's Known Exploited Vulnerabilities Catalog on 2022-03-31, and used in campaigns attributed to Chinese actors, including a U.S. indictment of a Chinese hacker for exploiting the flaw.

Do: Upgrade Sophos Firewall to a fixed release (v18.5 MR4 or later, per Sophos' patch instructions). Until patched, restrict access to the User Portal and Webadmin to trusted management networks or VPN clients and remove any direct internet exposure to these services. Review device and authentication logs for signs of exploitation, including unexpected or modified administrator accounts and configuration changes, and follow the vendor/CISA required action to apply updates.

9.8100% KEV PoC ×2
  • Sophos Firewall (SFOS) v18.5 MR3 and older
largetens of thousands of internet-exposed User Portal/Webadmin instances among hundreds of thousands of deployed Sophos Firewall appliances
CVE-2022-26871
Unauthenticated Arbitrary File Upload RCE in Trend Micro Apex Central

CVE-2022-26871 is a critical (CVSS 9.8) arbitrary file upload flaw (CWE-345, insufficient verification of data authenticity) in Trend Micro Apex Central, the central management console for Trend Micro's endpoint protection. An unauthenticated remote attacker can send an upload request to a network-accessible interface without any credentials or user interaction, uploading an arbitrary file that can lead to remote code execution on the server. Successful exploitation gives the attacker code execution with high impact to confidentiality, integrity and availability on the affected management server, potentially providing a foothold into the wider network it manages. Organizations running Trend Micro Apex Central on-premise are affected; CISA also lists Apex One in the product CPE data, while CISA's affected-product entry names Apex Central. The flaw was added to the CISA Known Exploited Vulnerabilities Catalog on 2022-03-31, indicating observed exploitation in the wild, with EPSS estimating a 19.6% probability of exploitation within 30 days; no public PoC is known.

Do: Apply the updated Apex Central release per Trend Micro's security advisory and the CISA KEV required action (apply updates per vendor instructions); confirm with the vendor which build addresses CVE-2022-26871 for your deployment. Until patched, restrict internet exposure of the Apex Central management console to trusted networks and review the server for unexpected uploaded files or web/server processes launching children, given confirmed in-the-wild exploitation. Organizations managing Apex One endpoints via Apex Central should ensure the management server is prioritized, since compromise could expose endpoint fleet management functions.

9.820% KEV
  • Trend Micro Apex Central
  • Trend Micro Apex One
moderate≈1,000–10,000 on-premise management servers worldwide (estimated)
Full article498 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency (CISA) added seven vulnerabilities to its catalog of Known Exploited Vulnerabilities.

The vulnerabilities added include an arbitrary file upload vulnerability in Trend Micro Apex Central; an insufficient access control issue in Dell's dbutil driver; an improper authorization vulnerability in QNAP NAS instances running HBS 3; an authentication bypass vulnerability in the User Portal and Webadmin of Sophos Firewall; a vulnerability in Microsoft Windows User Profile Service and two authentication bypass vulnerabilities involving Dasan's Gigabit Passive Optical Network (GPON) Routers.

All of the vulnerabilities have remediation dates of April 21, and CISA said the seven additions were “based on evidence of active exploitation.”

“These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise,” CISA explained. 

Sophos released a security advisory about CVE-2022-1040, noting that it was reported through their bug bounty program and has been fixed.

“Sophos has observed this vulnerability being used to target a small set of specific organizations primarily in the South Asia region,” the notice added, highlighting that it has a 9.8 CVSS score.

Trend Micro also released its own notice on CVE-2022-26871, noting that it has a CVSS score of 8.6. 

“Trend Micro has observed an active attempt of exploitation against this vulnerability in-the-wild (ITW) in a very limited number of instances, and we have been in contact with these customers already. All customers are strongly encouraged to update to the latest version as soon as possible,” the company said. 

The QNAP vulnerability relates to an issue that was identified and patched in April 2021. Last year, Palo Alto said ransomware gangs like eCh0raix were targeting the vulnerability

Bud Broomhead, CEO at security firm Viakoo, said two of the seven vulnerabilities can’t be patched due to the product being obsoleted and the manufacturer not being able to provide a patch, referencing the two vulnerabilities affecting Dasan's routers.

Dasan told VPNmentor in March that, using its sales records, it believes about 240,000 units are impacted by the vulnerabilities. But they said “given the relative maturity of the products in their lifecycle, we think the impact is limited to even fewer devices.”

“Unlike most of the known exploited vulnerabilities in the CISA catalog, two of these vulnerabilities (Trend Micro CVE-2022-26871 and Sophos CVE-2022-1040) were just discovered in the last few days,” Broomhead explained. 

“This means the timing of developing a patch, distributing it, and deploying it is much shorter than with others. Organizations should be extra vigilant with these patches as the normal testing process may have been rushed given how these are brand new, being exploited, and high severity.”

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-adds-seven-bugs-to-known-exploited-vulnerabilities-catalog