ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds SonicWall SonicOS, ImageMagick and Linux Kernel bugs to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2016-3714CVE-2017-1000253CVE-2024-40766

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-3714
Command Injection RCE in ImageMagick Image Coders (ImageTragick)

ImageTragick (CVE-2016-3714) is an improper input validation flaw in ImageMagick's EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders that allows shell metacharacters embedded in a crafted image to be passed to the command shell. It is triggered whenever ImageMagick processes a malicious image file — typically when a web application converts or thumbnails user-supplied uploads or URLs. A successful attacker gains arbitrary command and code execution on the host running ImageMagick, with the privileges of that process. Anyone running affected versions of ImageMagick — before 6.9.3-10 in the 6.x line or before 7.0.1-1 in the 7.x line, including builds shipped with Ubuntu, Debian, openSUSE/Leap and SUSE Linux Enterprise Server — is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-09, and EPSS places its 30-day exploitation probability at 97.5% (100th percentile), consistent with active exploitation.

Do: Upgrade ImageMagick to 6.9.3-10 or later (6.x) or 7.0.1-1 or later (7.x), or apply the security updates issued by Ubuntu, Debian, openSUSE and SUSE. As an interim mitigation, disable or restrict the vulnerable coders (EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, PLT) via ImageMagick's policy.xml and avoid passing user-controlled filenames or URLs unfiltered to ImageMagick. Prioritize auditing internet-facing services that process user-uploaded images (CMSs, forums, image pipelines), which are the typical delivery path for this flaw.

8.497% KEV
  • ImageMagick (6.x line) before 6.9.3-10
  • ImageMagick (7.x line) 7.x before 7.0.1-1
  • Canonical Ubuntu Linux
  • +3 more
massmillions of installations worldwide (ImageMagick ships by default with Ubuntu, Debian, openSUSE and SLES and underpins image processing on a very large share…
CVE-2017-1000253
Linux Kernel PIE Stack Buffer Corruption Enables Local Privilege Escalation

CVE-2017-1000253 is a memory-corruption flaw (CWE-119) in the Linux kernel's ELF binary loader: when CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE is enabled with a top-down allocation strategy, load_elf_binary() maps a PIE (position-independent executable) immediately below mm->mmap_base without reserving space for the entire binary, so subsequent PT_LOAD segments are mapped above mmap_base into the gap reserved between the stack and the binary. Any local user can trigger the flaw simply by executing a PIE binary on an affected unpatched long-term kernel. The resulting corruption of the stack region yields local privilege escalation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, local attack vector, low privileges required). Affected systems are Linux distributions running long-term kernels that lack the April 2015 fix commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 — notably Red Hat Enterprise Linux and CentOS kernels — where the fix was applied but not recognized as a security issue at the time. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-09-09 with known ransomware use, and EPSS assigns a 10.7% probability of exploitation within 30 days (96th percentile); no public PoC is known.

Do: Update affected systems to kernel packages that include commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (upstream since April 2015 and backported to Linux 3.10.77), or move to a currently supported kernel branch; per CISA KEV, apply vendor mitigations or discontinue use of the product if mitigations are unavailable. Prioritize legacy RHEL/CentOS and other long-lived LTS deployments — especially internet-facing or ransomware-targeted servers — and check whether running kernels are built with CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE and allow unprivileged users to execute PIE binaries.

7.811% KEV ransomware
  • linux kernel long-term kernels without fix commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (fixed upstream April 2015; backported to Linux 3.10.77 in May 2015)
  • redhat enterprise linux kernels not carrying the backported fix (exact package versions per vendor advisory)
  • centos kernels not carrying the backported fix (exact package versions per vendor advisory)
massmillions of servers and appliances on unpatched legacy LTS kernels (enterprise Linux installed base)
CVE-2024-40766
Improper Access Control in SonicWall SonicOS Management (Gen 5/6/7 Firewalls)

CVE-2024-40766 is an improper access control flaw (CWE-284) in SonicWall SonicOS management access that can allow unauthorized access to protected resources and, under specific conditions, crash the affected firewall. It is network-exploitable without privileges or user interaction per its CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) and affects Gen 5 and Gen 6 appliances as well as Gen 7 devices running SonicOS 7.0.1-5035 or older. A successful attacker gains unauthorized access to resources behind or on the appliance and can potentially take the firewall offline, creating opportunities for follow-on attacks such as VPN account compromise and ransomware deployment. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-09 with known ransomware use, and recent reporting ties Akira ransomware activity — including MFA bypass on SonicWall VPNs affecting over 100 accounts — to this legacy bug combined with password reuse. No public PoC is known, but EPSS assigns an ~18.2% probability of exploitation within 30 days (97th percentile).

Do: Upgrade Gen 7 appliances to SonicOS 7.0.1-5037 or later (the fixed release beyond the affected 7.0.1-5035) and move Gen 5/6 devices to the latest SonicOS release SonicWall supports for those generations; per CISA KEV guidance, apply vendor mitigations or discontinue use if patching is not possible. Restrict WAN-side management and SSLVPN access to trusted sources, audit VPN accounts for password reuse, rotate credentials and any locally stored recovery codes, and review logs for signs of Akira-related compromise such as MFA bypass or disabled EDR agents.

9.818% KEV ransomware
  • SonicWall SonicOS (Gen 5 firewalls) Gen 5 appliances, all versions per the CISA advisory
  • SonicWall SonicOS (Gen 6 firewalls) Gen 6 appliances, all versions per the CISA advisory
  • SonicWall SonicOS (Gen 7 firewalls) SonicOS 7.0.1-5035 and older
mass≈100,000–500,000 internet-exposed SonicWall firewalls/SSLVPN endpoints (installed base of 1M+ appliances)
Full article407 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 10, 2024

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SonicWall SonicOS, ImageMagick and Linux Kernel bugs to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall SonicOS, ImageMagick and Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these vulnerabilities:

CVE-2016-3714 flaw (aka ImageTragick), in the popular image manipulation software ImageMagick could allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka “ImageTragick.” Attackers can exploit the flaw to take over websites running the widely used image-enhancing app. The vulnerability in ImageMagick App allows attackers to run arbitrary code on the targeted web servers that rely on the app for resizing or cropping user-uploaded images.

CVE-2017-1000253 flaw was discovered by researchers with Qualys Research Labs and affects all Linux distributions that have not fixed their kernels after a commit released on April 14, 2015. Attackers can exploit the vulnerability to escalate privileges. The issue resides in the way the kernel loads ELF executables and is triggered by applications that have been built as Position Independent Executables (PIEs).

“A flaw was found in the way the Linux kernel loaded ELF executables. Provided that an application was built as Position Independent Executable (PIE), the loader could allow part of that application’s data segment to map over the memory area reserved for its stack, potentially resulting in memory corruption.” reads the advisory published on RedHat. “An unprivileged local user with access to SUID (or otherwise privileged) PIE binary could use this flaw to escalate their privileges on the system.”

CVE-2024-40766  is an Improper Access Control Vulnerability impacting SonicWall SonicOS. SonicWall warns that a recently fixed access control flaw, tracked as CVE-2024-40766 (CVSS v3 score: 9.3), in SonicOS is now potentially exploited in attacks.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by September 30, 2024.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/168251/security/u-s-cisa-adds-sonicwall-sonicos-imagemagick-and-linux-kernel-bugs-to-its-known-exploited-vulnerabilities-catalog.html