ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Urges Agencies to Patch Critical "Array Networks" Flaw Amid Active Attacks

criticalVulnerability exploited in the wildimportance 60CVE-2023-28461CVE-2023-45727CVE-2023-27997

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27997
Pre-Auth Heap Buffer Overflow RCE in Fortinet FortiOS/FortiProxy SSL-VPN

CVE-2023-27997 is a heap-based buffer overflow (CWE-122, with associated out-of-bounds write CWE-787) in the SSL-VPN component of Fortinet FortiOS and FortiProxy, reachable by unauthenticated users. A remote attacker can trigger it with specially crafted requests to the SSL-VPN web interface, gaining the ability to execute arbitrary code or commands on the gateway. Full control of an edge VPN/firewall appliance enables credential theft, session hijacking, and pivoting into the protected network, which makes the bug attractive to ransomware operators. Any organization exposing the SSL-VPN portal on the affected FortiOS builds (7.2.4 and below, 7.0.11 and below, 6.4.12 and below, 6.0.16 and below) or FortiProxy builds (7.2.3 and below, 7.0.9 and below, 2.0.12 and below, and 1.1/1.2 all versions) is potentially exposed. The flaw is under active exploitation: CISA added it to the KEV on 2023-06-13 with known ransomware use, EPSS estimates an ~86% probability of exploitation within 30 days (100th percentile), and reporting indicates it was likely being exploited in the wild, with Fortinet also warning that some attackers retained access to FortiGate devices even after patching.

Do: Apply Fortinet's updates to all SSL-VPN-enabled FortiOS and FortiProxy appliances as required by the CISA KEV listing, upgrading each affected branch beyond the listed versions (end-of-life FortiProxy 1.1/1.2 requires migration to a supported release); if SSL-VPN is not needed, disable the web portal or restrict it to trusted source addresses. After patching, hunt for signs of compromise and rotate credentials and VPN-related secrets, since Fortinet warned that some attackers retained access to FortiGate devices post-patching.

9.886% KEV ransomware
  • Fortinet FortiOS (SSL-VPN) 7.2.4 and below; 7.0.11 and below; 6.4.12 and below; 6.0.16 and below
  • Fortinet FortiProxy (SSL-VPN) 7.2.3 and below; 7.0.9 and below; 2.0.12 and below; 1.2 (all versions); 1.1 (all versions)
masson the order of several hundred thousand internet-exposed SSL-VPN endpoints (≈300k–500k per public scans)
CVE-2023-28461
Unauthenticated RCE in Array Networks AG/vxAG SSL VPN Gateways (ArrayOS)

CVE-2023-28461 is a critical (CVSS 9.8) missing-authentication flaw in Array Networks' AG series and virtual vxAG SSL VPN gateways running ArrayOS 9.4.0.481 and earlier. An unauthenticated remote attacker sends an HTTP request to a vulnerable URL containing a 'flags' attribute in an HTTP header, which allows browsing the filesystem on the SSL VPN gateway; vendor and CERT reporting indicate this can be leveraged into full remote code execution, and JPCERT has confirmed active command-injection attacks. Successful exploitation gives the attacker code execution on the appliance, compromising the VPN gateway and potentially providing a foothold into the protected internal network. Any organization running an affected AG/vxAG gateway is exposed; these are enterprise SSL VPN appliances, with notable deployments in Japan and the wider Asia-Pacific region. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-11-25 (ransomware use known), JPCERT/CC reports widespread exploitation, Chinese-linked activity including MirrorFace targeting Japanese firms has been reported, and EPSS places the 30-day exploitation probability at 68.1%.

Do: Upgrade AG/vxAG gateways to a fixed ArrayOS release per Array Networks' instructions — as of the 2023-03-09 advisory a fixed release was pending, so apply any release newer than 9.4.0.481 once available; if mitigations are unavailable, discontinue use per the CISA KEV required action, and federal agencies should follow CISA's directive to patch. Review gateway logs and downstream systems for signs of exploitation, and treat any compromised appliance as a potential network foothold given confirmed ransomware use.

9.868% KEV ransomware
  • Array Networks AG series and vxAG SSL VPN gateways (ArrayOS) 9.4.0.481 and earlier
moderatelikely on the order of thousands (roughly 1,000–10,000) of internet-exposed AG/vxAG gateway appliances, each typically serving many remote users (estimate)
CVE-2023-45727
Unauthenticated XXE File-Read in North Grid Proself (CVE-2023-45727)

Proself, a self-hosted groupware/webmail product line from Japan's North Grid, improperly restricts XML external entity references (CWE-611) when processing XML data submitted to the server. A remote, unauthenticated attacker can send a specially crafted request containing malformed XML that triggers XXE resolution, allowing the attacker to read arbitrary files on the server, including files containing account information. Successful exploitation therefore primarily threatens confidentiality — exposed account credentials and sensitive data on the server — with no impact on integrity or availability per the CVSS 3.1 vector (7.5, AV:N/AC:L/PR:N/UI:N). Organizations running Proself Enterprise/Standard Edition 5.62 or earlier, Gateway Edition 1.65 or earlier, or Mail Sanitize Edition 1.08 or earlier are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-12-03, confirming exploitation in the wild, and EPSS estimates a 3.5% probability of exploitation in the next 30 days (89th percentile); no public PoC is known.

Do: Upgrade all Proself editions to fixed releases per North Grid's guidance — beyond Ver5.62 for Enterprise/Standard, beyond Ver1.65 for Gateway, and beyond Ver1.08 for Mail Sanitize — or discontinue use of the product if mitigations are unavailable, per CISA's required action. Prioritize internet-facing Proself instances, review web/application logs for suspicious XML-containing requests, and rotate exposed account credentials since account information files are the primary target of this file-read flaw.

7.54% KEV
  • North Grid Proself Enterprise/Standard Edition Ver5.62 and earlier
  • North Grid Proself Gateway Edition Ver1.65 and earlier
  • North Grid Proself Mail Sanitize Edition Ver1.08 and earlier
nichelikely on the order of hundreds of internet-exposed deployments worldwide (niche Japanese self-hosted product)
Full article405 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 26, 2024Vulnerability / Network Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched critical security flaw impacting Array Networks AG and vxAG secure access gateways to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.

The vulnerability, tracked as CVE-2023-28461 (CVSS score: 9.8), concerns a case of missing authentication that could be exploited to achieve arbitrary code execution remotely. Fixes (version 9.4.0.484) for the security shortcoming were released by the network hardware vendor in March 2023.

"Array AG/vxAG remote code execution vulnerability is a web security vulnerability that allows an attacker to browse the filesystem or execute remote code on the SSL VPN gateway using flags attribute in HTTP header without authentication," Array Networks said. "The product can be exploited through a vulnerable URL."

The inclusion to KEV catalog comes shortly after cybersecurity company Trend Micro revealed that a China-linked cyber espionage group dubbed Earth Kasha (aka MirrorFace) has been exploiting security flaws in public-facing enterprise products, such as Array AG (CVE-2023-28461), Proself (CVE-2023-45727), and Fortinet FortiOS/FortiProxy (CVE-2023-27997), for initial access.

Earth Kasha is known for its extensive targeting of Japanese entities, although, in recent years, it has also been observed attacking Taiwan, India, and Europe.

Earlier this month, ESET also disclosed an Earth Kasha campaign that targeted an unnamed diplomatic entity in the European Union to deliver a backdoor known as ANEL by using as lure the upcoming World Expo 2025 that's scheduled to take place in Osaka, Japan, starting April 2025.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the patches by December 16, 2024, to secure their networks.

The disclosure comes as 15 different Chinese hacking groups out of a total of 60 named threat actors have been linked to the abuse of at least one of the top 15 routinely exploited vulnerabilities in 2023, according to VulnCheck.

The cybersecurity company said it has identified over 440,000 internet-exposed hosts that are potentially susceptible to attacks.

"Organizations should evaluate their exposure to these technologies, enhance visibility into potential risks, leverage robust threat intelligence, maintain strong patch management practices, and implement mitigating controls, such as minimizing internet-facing exposure of these devices wherever possible," VulnCheck's Patrick Garrity said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/11/cisa-urges-agencies-to-patch-critical.html