Security Affairs newsletter Round 444 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-46604 | Unauthenticated RCE in Apache ActiveMQ via OpenWire Deserialization CVE-2023-46604 is a critical deserialization flaw (CWE-502) in the Java OpenWire protocol marshaller of Apache ActiveMQ that permits unauthenticated remote code execution (CVSS 9.8). An attacker with network access to either a Java-based OpenWire broker or client can manipulate serialized class types in the OpenWire protocol, causing the peer to instantiate arbitrary classes on the classpath and execute arbitrary shell commands. Successful exploitation yields full command execution on the target broker or client, with no authentication or user interaction required. Affected parties include anyone running ActiveMQ broker or Java client versions prior to 5.15.16, 5.16.7, 5.17.6, or 5.18.3, as well as NetApp E-Series products and Debian packages that ship affected ActiveMQ/OpenWire components. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-11-02 with known ransomware use (RansomHub), and has been used to drop Kinsing malware, Godzilla web shells, and the DripDropper implant, in some cases with attackers patching the flaw post-exploitation to lock out competing intruders. Do: Upgrade all ActiveMQ brokers and Java OpenWire clients to 5.15.16, 5.16.7, 5.17.6, or 5.18.3 (or later), and apply the relevant NetApp E-Series and Debian updates for bundled components; restrict the OpenWire port (default TCP 61616) from untrusted networks. Hunt for indicators of the documented campaigns (Godzilla web shells, Kinsing malware, DripDropper, RansomHub) and verify the broker's current version, since attackers have been observed patching the flaw post-exploitation to hide from defenders. The CISA KEV listing means federal agencies must apply vendor mitigations or discontinue use of the product. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed OpenWire brokers (order of 10,000–100,000 by public scans), plus uncounted internal deployments and bundled NetApp/Debian… | |
| CVE-2023-46747 | F5 BIG-IP TMUI Authentication Bypass Enables Unauthenticated RCE CVE-2023-46747 is a critical authentication bypass (CVSS 9.8) in the F5 BIG-IP Configuration Utility (TMUI) affecting most BIG-IP modules, including LTM, APM, DNS, AWAF, AFM, ASM, and SSL Orchestrator. By sending undisclosed, specially crafted requests to the TMUI, an attacker with network access to the BIG-IP management port and/or self IP addresses bypasses authentication and can execute arbitrary system commands on the system. No privileges or user interaction are required, and successful exploitation effectively yields full control of the affected BIG-IP deployment. Any organization running vulnerable BIG-IP software is exposed, particularly enterprises, service providers, and government agencies whose management interface or self IPs are reachable. The flaw is being actively exploited: it was added to CISA KEV on 2023-10-31 with known ransomware use, public PoC code exists, and reporting links it to Chinese nation-state actors targeting defense and government networks. Do: Upgrade all affected BIG-IP systems to the fixed releases identified in F5 advisory K13763 (17.1.0.1, 16.1.4, 15.1.9, 14.1.5.5, or 13.1.5.1 depending on the train, or later); the CISA KEV listing makes remediation mandatory for federal agencies. As an interim mitigation, restrict network access to the TMUI management port and self IP addresses and apply F5's documented mitigation guidance. Given active nation-state and ransomware exploitation, also audit appliances for indicators of compromise such as unexpected accounts, scheduled tasks, and configuration changes. | 9.8 | 97% | KEV ransomware PoC ×2 |
| largetens of thousands of internet-exposed BIG-IP systems (10k-100k), with a total enterprise installed base plausibly in the hundreds of thousands |
Full article388 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 05, 2023

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
Cybercrime
New Hunters International ransomware possible rebrand of Hive
Boeing Says Its Services Division Was Hit by Cyberattack
Hackers Accessed 632,000 Email Addresses at US Justice, Defense Departments
Dutch hacker jailed for extortion, selling stolen data on RaidForums
US Harbors Prolific Malicious Link Shortening Service
‘Corrupt’ cop jailed for tipping off pal to EncroChat dragnet
Malware
Ukrainian hackers disrupt internet providers in Russia-occupied territories
BiBi-Linux: A New Wiper Dropped By Pro-Hamas Hacktivist Group
Who killed Mozi? Finally putting the IoT zombie botnet in its grave
AridViper, an intrusion set allegedly associated with Hamas
WhatsApp spy mod spreads through Telegram, attacks Arabic-speaking users
Elastic catches DPRK passing out KANDYKORN
Hacking
Refresh: Compromising F5 BIG-IP With Request Smuggling | CVE-2023-46747
Suspected Exploitation of Apache ActiveMQ CVE-2023-46604
Unauthorized Access to Okta’s Support Case Management System: Root Cause and Remediation
Looney Tunables Vulnerability Exploited by Kinsing
A cascade of compromise: unveiling Lazarus’ new campaign
Oldham Council facing 10,000 cyber attacks a day, report says
Russian Reshipping Service ‘SWAT USA Drop’ Exposed
Intelligence and Information Warfare
Fifth-Generation Warfare: AI in the Election Cycle
MuddyWater eN-Able spear-phishing with new TTPs
Russian TA499 Targets North American and European Countries
Hackers are under investigation
ISRAEL GAZA CONFLICT : THE CYBER PERSPECTIVE
Cybersecurity
7th Annual Hacker Powered Security Report
Your iPhone has a fatal security flaw — how to fix it immediately
Internet access in Gaza partially restored after blackout
The Race to Save Our Secrets From the Computers of the Future
ODNI, Pentagon reveal FY23 intelligence budget at nearly $100 billion
Is state intervention needed for cyber insurance?
PSA: Your chat and call apps may leak your IP address
German government reports risk of cyber threats higher than ever
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/153643/breaking-news/security-affairs-newsletter-round-444-by-pierluigi-paganini-international-edition.html