ZeroHour
Security Affairspublished ()ingested @securityaffairs

UK NCSC agency warns of APTs exploiting Enterprise VPN vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-13379
Unauthenticated Path Traversal in Fortinet FortiOS SSL VPN

CVE-2018-13379 is a path traversal flaw (CWE-22) in the Fortinet FortiOS SSL VPN web portal that allows an unauthenticated attacker to download FortiOS system files via specially crafted HTTP resource requests. By traversing directories through crafted requests to the exposed web portal, the attacker can retrieve sensitive files, a technique publicly documented as yielding the SSL VPN session file containing usernames and passwords in plaintext. Any organization running the SSL VPN web portal on a FortiGate appliance is affected, and risk is highest where the portal is directly reachable from the internet. The flaw is confirmed in the wild: it was added to the CISA KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. No public PoC is listed in the provided data, but credential theft tied to this bug has been widely reused by threat actors.

Do: Apply the patched FortiOS release per Fortinet's vendor advisory immediately, as this is a CISA KEV required action; if the fixed version is not known from this data, follow Fortinet's FG-IR-18-384 advisory for the correct upgrade path. Rotate SSL VPN credentials and review VPN access logs for path-traversal requests, since successful exploitation exposes plaintext session credentials, and restrict SSL VPN portal exposure to trusted sources where possible.

9.8100% KEV ransomware
  • Fortinet FortiOS
mass≈500,000 internet-exposed FortiOS SSL VPN portals (Fortinet cited ~480,000 affected devices)
CVE-2018-13382
Unauthenticated SSL VPN Account-Takeover Flaw in Fortinet FortiOS and FortiProxy

CVE-2018-13382 is an improper authorization flaw (CWE-863) in the SSL VPN web portal of Fortinet FortiOS and FortiProxy that fails to properly authorize password-change requests. An unauthenticated attacker who can reach the SSL VPN web portal can send specially crafted HTTP requests to modify the password of an SSL VPN web-portal user without knowing the existing credentials. This effectively hands the attacker control of the victim's VPN account, enabling login through the portal and potential follow-on access to the internal network, consistent with the integrity-only CVSS 3.1 score of 7.5 (High). Any organization running affected versions - FortiOS 6.0.0-6.0.4, 5.6.0-5.6.8 or 5.4.1-5.4.10, or FortiProxy 2.0.0, 1.2.0-1.2.8, 1.1.0-1.1.6 or 1.0.0-1.0.7 - with the SSL VPN web portal enabled is affected. The flaw is actively exploited: it was added to CISA's KEV catalog on 2022-01-10 with known ransomware use, EPSS estimates an 81.7% probability of exploitation within 30 days, and NSA/NCSC advisories warn that APT groups are exploiting VPN vulnerabilities of this kind.

Do: Apply updates to all affected FortiOS and FortiProxy deployments per Fortinet's instructions, as this is the CISA KEV required action, prioritizing internet-facing SSL VPN portals. Until patched, limit exposure of the SSL VPN web portal and audit authentication logs for unexpected password changes or unauthenticated requests to the portal. Given known ransomware and APT exploitation, force a password reset on VPN accounts whose credentials may have been tampered with.

7.582% KEV ransomware
  • Fortinet FortiOS 6.0.0-6.0.4, 5.6.0-5.6.8, 5.4.1-5.4.10
  • Fortinet FortiProxy 2.0.0, 1.2.0-1.2.8, 1.1.0-1.1.6, 1.0.0-1.0.7
masshundreds of thousands of internet-exposed FortiGate/FortiProxy SSL VPN endpoints (estimate)
CVE-2018-13383
Out-of-Bounds Write in Fortinet FortiOS and FortiProxy SSL VPN Web Service

CVE-2018-13383 is a heap buffer overflow (out-of-bounds write, CWE-787) in the SSL VPN web portal of Fortinet FortiOS and FortiProxy. It is triggered when a logged-in SSL VPN user's web session processes crafted JavaScript supplied by a remote site, corrupting heap memory in the SSL VPN web service. An attacker can crash the SSL VPN web service, terminating access for logged-in users, and Fortinet's advisory indicates the memory corruption may allow arbitrary code execution via a crafted JavaScript payload. Organizations running affected FortiOS releases on FortiGate appliances with the SSL VPN web portal enabled, and organizations running FortiProxy secure web gateways, are affected. Exploitation is active: the flaw was added to CISA KEV on 2022-01-10 with known ransomware use, the required action is to apply vendor updates, and EPSS assigns a 33.6% 30-day exploitation probability (98th percentile).

Do: Apply Fortinet's fixed releases per the vendor advisory (FortiGate/FortiOS: 6.2.1+, 6.0.5+, 5.6.8+, or 5.4.11+ as applicable; FortiProxy: 2.0.1+ or 1.2.9+), consistent with the CISA KEV required action. Until patched, restrict exposure of the SSL VPN web portal to the internet and monitor the appliance for signs of compromise, given the known ransomware use. Prioritize internet-facing SSL VPN endpoints in remediation ordering because of the elevated EPSS score.

6.534% KEV ransomware
  • Fortinet FortiOS Multiple releases including 6.2.0, 6.0.0-6.0.4, 5.6.0-5.6.7, and 5.4.0-5.4.10 (ranges per Fortinet advisory; source data does not specify versions)
  • Fortinet FortiProxy 2.0.0 and 1.2.x releases (ranges per Fortinet advisory; source data does not specify versions)
masslikely several hundred thousand internet-exposed FortiGate SSL VPN portals and FortiProxy gateways, out of a Fortinet installed base in the millions of devices
CVE-2019-11510
Unauthenticated Arbitrary File Read in Ivanti Pulse Connect Secure VPN

Ivanti Pulse Connect Secure, an enterprise SSL VPN appliance, contains an arbitrary file read vulnerability (CWE-22, path traversal) that requires no authentication. An unauthenticated remote attacker with network access to the appliance over HTTPS can send a specially crafted URI containing traversal sequences to read arbitrary files from the device. The attacker gains access to sensitive appliance files, potentially including configuration or credential material useful for further compromise, and CISA records known ransomware use of this flaw. Any organization running Pulse Connect Secure, especially gateways exposed to the internet for remote access, is affected. Exploitation is established: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a 100% probability of exploitation in the next 30 days, and no public PoC is known.

Do: Apply updates per Ivanti's instructions, the required action in the CISA KEV entry, prioritizing internet-facing Pulse Connect Secure gateways, and consult the vendor advisory for the applicable fixed release since no version range is provided here. Where patching is not immediate, restrict HTTPS access to the appliance and hunt for signs of exploitation (unexpected file reads, anomalous VPN logins or sessions, and follow-on ransomware activity), as CISA reports known ransomware use.

10.0100% KEV ransomware PoC ×2
  • Ivanti Pulse Connect Secure
largeTens of thousands of internet-exposed gateways (order of 10,000-100,000 systems; each typically serves hundreds of VPN users, so potentially millions of users)
CVE-2019-11539
Authenticated Command Injection in Ivanti Pulse Connect Secure and Policy Secure

Ivanti/Pulse Secure Pulse Connect Secure and Pulse Policy Secure contain an OS command injection flaw (CWE-78) in the admin web interface. An authenticated attacker can send crafted requests to the administrative web interface to inject and execute arbitrary operating-system commands on the appliance. Successful exploitation gives full control of the VPN or network access control appliance, enabling data theft, persistence, and pivoting into the corporate intranet. Any organization running an affected Pulse Connect Secure (9.0RX/8.3RX/8.2RX/8.1RX) or Pulse Policy Secure (9.0RX/5.4RX/5.3RX/5.2RX/5.1RX) release is exposed, especially internet-facing VPN gateways. Exploitation is very active: the bug is in CISA's KEV, public research chained it with CVE-2019-11510 into an unauthenticated RCE chain, APT groups and Black Kingdom ransomware operators have been reported exploiting Pulse VPN flaws, and EPSS estimates a 98.5% probability of exploitation within 30 days.

Do: Upgrade Pulse Connect Secure to 9.0R3.4+ (or 8.3R7.1+, 8.2R12.1+, 8.1R15.1+) and Pulse Policy Secure/Policy Secure to 9.0R3.2+ (or 5.4R7.1+, 5.3R12.1+, 5.2R12.1+, 5.1R15.1+) per vendor instructions. Restrict exposure of the admin web interface to trusted networks, rotate administrative credentials, and hunt for signs of compromise on appliances that were internet-exposed, particularly where the chained CVE-2019-11510 file-read flaw may also have been exploited.

7.299% KEV ransomware PoC ×2
  • ivanti / pulsesecure Pulse Connect Secure 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, 8.1RX before 8.1R15.1
  • ivanti / pulsesecure Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, 5.1RX before 5.1R15.1
  • ivanti / pulsesecure Policy Secure Same ranges as Pulse Policy Secure (9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, 5.1RX before 5.1R15.1)
masson the order of 100,000 to several hundred thousand internet-exposed Pulse Connect Secure/Policy Secure appliances
CVE-2019-1579
Format String RCE in Palo Alto Networks PAN-OS GlobalProtect Portal/Gateway

CVE-2019-1579 is a remote code execution vulnerability (CWE-134, format string) in Palo Alto Networks PAN-OS that is exposed on devices where the GlobalProtect Portal or GlobalProtect Gateway interface is enabled. An attacker can trigger it remotely by sending specially crafted format-string input to the network-facing GlobalProtect portal or gateway interface. Successful exploitation allows arbitrary code execution on the firewall, giving the attacker control of the device and a foothold into the protected network. Any organization running PAN-OS with the GlobalProtect Portal or Gateway interface enabled is affected; deployments without those interfaces enabled are not exposed to this flaw. Exploitation is confirmed: the vulnerability is in CISA's KEV (added 2022-01-10) with known ransomware use, and EPSS assigns a 46.2% probability of exploitation within 30 days (99th percentile), although no public PoC is catalogued.

Do: Upgrade PAN-OS per Palo Alto Networks' security advisory, as required by CISA's KEV required action; first inventory devices with the GlobalProtect Portal or Gateway interface enabled and prioritize internet-facing ones. Until patched, restrict or firewall access to the GlobalProtect interfaces, and hunt for signs of compromise given the known ransomware association.

8.146% KEV ransomware PoC
  • Palo Alto Networks PAN-OS
largetens of thousands of internet-exposed GlobalProtect portals/gateways (likely more including internally deployed gateways)
Full article366 words · extracted from securityaffairs.com · click to collapse

The UK’s National Cyber Security Centre (NCSC) warns of attacks exploiting recently disclosed VPN vulnerabilities in Fortinet, Palo Alto Networks and Pulse Secure

According to the UK’s National Cyber Security Centre (NCSC), advanced persistent threat (APT) groups have been exploiting recently disclosed VPN vulnerabilities in enterprise VPN products in attacks in the wild. Threat actors leverage VPN vulnerabilities in Fortinet, Palo Alto Networks and Pulse Secure, to breach into the target networks.

This week the NCSC issued an alert to warn organizations using the vulnerable products.

“The NCSC is investigating the exploitation, by Advanced Persistent Threat (APT) actors, of known vulnerabilities affecting Virtual Private Network (VPN) products from vendors Pulse securePalo Alto and Fortinet.” reads the alert issued by the NCSC.

“This activity is ongoing, targeting both UK and international organisations. Affected sectors include government, military, academic, business and healthcare,”

The UK agency reported that APT groups target several vulnerabilities, including CVE-2019-11510 and CVE-2019-11539 in Pulse Secure VPN solutions, and CVE-2018-13379,

The CVE-2018-13379 is a path traversal vulnerability in the FortiOS SSL VPN web portal that could be exploited by an unauthenticated attacker to download FortiOS system files. The CVE-2018-13379 flaw could be exploited to obtain administrator credentials in plain text.

The CVE-2019-11510 flaw in Pulse Connect Secure is a critical arbitrary file read vulnerability.

APT groups also exploit CVE-2018-13382, CVE-2018-13383, and CVE-2019-1579, in Palo Alto Networks products.

The vulnerabilities were first reported in July by researchers Orange Tsai and Meh Chang from DEVCORE that found several flaws in Fortinet, Palo Alto Networks and Pulse Secure products. The issues could be exploited by threat actors to access corporate networks and steal sensitive documents.

“Users of these VPN products should investigate their logs for evidence of compromise, especially if it is possible that patches were not applied immediately after their release.” concludes the NCSC.

“Apart from specific product advice below, administrators should also look for evidence of compromised accounts in active use, such as anomalous IP locations or times.

Snort rules are available in open source, but may not pick up events for exploits over HTTPS.”

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – vBulletin, data breach)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/92177/hacking/ncsc-alert-vpn-vulnerabilities.html