ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds Microsoft Exchange and Cisco ASA and FTD bugs to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2020-3259CVE-2024-21410

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3259
Unauthenticated Memory-Disclosure Flaw in Cisco ASA and FTD Web Services

CVE-2020-3259 is an information-disclosure vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software, caused by a buffer-tracking error when the device parses invalid URLs. An unauthenticated, remote attacker can trigger it by sending a crafted GET request to the web services interface, which allows retrieval of the device's memory contents and disclosure of confidential information. Only devices with specific AnyConnect and WebVPN configurations are affected, but those configurations are common on ASA/FTD firewalls deployed as enterprise edge and remote-access VPN gateways. Exploitation is confirmed in the wild: CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-02-15 with known ransomware use, and the Akira ransomware group (which the FBI says has extorted $42 million across roughly 250 attacks since March 2023) is actively exploiting it, with LockBit also scanning for vulnerable Cisco ASA devices. EPSS assigns a 71.8% probability of exploitation within 30 days, and no public proof-of-concept code is known.

Do: Upgrade affected ASA and FTD devices to the fixed releases listed in Cisco's security advisory for CVE-2020-3259; if patching is delayed, disable or restrict the web services interface (WebVPN/AnyConnect) to trusted source networks. Per the CISA KEV required action, apply vendor mitigations or discontinue use where mitigations are unavailable. Prioritize internet-facing VPN gateways and hunt for exploitation indicators (anomalous GET requests to the web services interface) given active Akira and LockBit targeting.

7.572% KEV ransomware
  • Cisco Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
mass~100,000+ internet-exposed ASA/FTD devices with the web services (WebVPN/AnyConnect) interface enabled
CVE-2024-21410
Privilege Escalation via NTLM Relay Flaw in Microsoft Exchange Server

CVE-2024-21410 is a critical improper authentication flaw (CWE-287, CVSS 9.8) in on-premises Microsoft Exchange Server that enables NTLM credential relay attacks against the server's authentication, for example over SMTP. An attacker who can induce an NTLM authentication exchange can relay captured credentials to Exchange and impersonate another user, achieving an elevation of privilege without holding valid credentials themselves. Organizations running vulnerable on-premises Exchange — particularly internet-facing servers where Extended Protection for Authentication is not enforced — are affected. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-02-15, and the fix shipped in Microsoft's February 2024 Patch Tuesday release alongside roughly 90 other vulnerabilities; no public proof-of-concept code is known.

Do: Apply Microsoft's February 2024 Exchange Server security update immediately, prioritizing internet-facing servers; note that the update enables Extended Protection for Authentication (EPA) by default, so verify EPA is active and that clients, appliances, and load balancers relying on NTLM/SMTP authentication still function. Because the flaw is on CISA's KEV catalog, federal and high-risk operators must apply the vendor mitigations promptly or discontinue use if patching is not possible.

9.813% KEV
  • microsoft exchange server
large≈100,000 internet-exposed Exchange servers worldwide (public scan-based reporting; BSI counted 17,000+ in Germany alone)
Full article290 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 16, 2024

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Exchange and Cisco ASA and FTD bugs to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2020-3259 Cisco ASA and FTD Information Disclosure Vulnerability
  • CVE-2024-21410 Microsoft Exchange Server Privilege Escalation Vulnerability

The vulnerability CVE-2020-3259 is an information disclosure issue that resides in the web services interface of ASA and FTD. Cisco addressed the flaw in May 2020.

The vulnerability CVE-2024-21410 is a bypass vulnerability that can be exploited by an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both.

“An attacker could target an NTLM client such as Outlook with an NTLM credentials-leaking type vulnerability. The leaked credentials can then be relayed against the Exchange server to gain privileges as the victim client and to perform operations on the Exchange server on the victim’s behalf. For more information about Exchange Server’s support for Extended Protection for Authentication(EPA), please see Configure Windows Extended Protection in Exchange Server.” reads the advisory published by Microsoft.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix these vulnerabilities by March 7, 2024.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – Hacking, Known Exploited Vulnerabilities catalog)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/159245/security/cisa-exchange-cisco-asa-ftd-known-exploited-vulnerabilities-catalog.html