ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

SonicWall Probes Attack Using Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-13379
Unauthenticated Path Traversal in Fortinet FortiOS SSL VPN

CVE-2018-13379 is a path traversal flaw (CWE-22) in the Fortinet FortiOS SSL VPN web portal that allows an unauthenticated attacker to download FortiOS system files via specially crafted HTTP resource requests. By traversing directories through crafted requests to the exposed web portal, the attacker can retrieve sensitive files, a technique publicly documented as yielding the SSL VPN session file containing usernames and passwords in plaintext. Any organization running the SSL VPN web portal on a FortiGate appliance is affected, and risk is highest where the portal is directly reachable from the internet. The flaw is confirmed in the wild: it was added to the CISA KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. No public PoC is listed in the provided data, but credential theft tied to this bug has been widely reused by threat actors.

Do: Apply the patched FortiOS release per Fortinet's vendor advisory immediately, as this is a CISA KEV required action; if the fixed version is not known from this data, follow Fortinet's FG-IR-18-384 advisory for the correct upgrade path. Rotate SSL VPN credentials and review VPN access logs for path-traversal requests, since successful exploitation exposes plaintext session credentials, and restrict SSL VPN portal exposure to trusted sources where possible.

9.8100% KEV ransomware
  • Fortinet FortiOS
mass≈500,000 internet-exposed FortiOS SSL VPN portals (Fortinet cited ~480,000 affected devices)
CVE-2019-11510
Unauthenticated Arbitrary File Read in Ivanti Pulse Connect Secure VPN

Ivanti Pulse Connect Secure, an enterprise SSL VPN appliance, contains an arbitrary file read vulnerability (CWE-22, path traversal) that requires no authentication. An unauthenticated remote attacker with network access to the appliance over HTTPS can send a specially crafted URI containing traversal sequences to read arbitrary files from the device. The attacker gains access to sensitive appliance files, potentially including configuration or credential material useful for further compromise, and CISA records known ransomware use of this flaw. Any organization running Pulse Connect Secure, especially gateways exposed to the internet for remote access, is affected. Exploitation is established: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a 100% probability of exploitation in the next 30 days, and no public PoC is known.

Do: Apply updates per Ivanti's instructions, the required action in the CISA KEV entry, prioritizing internet-facing Pulse Connect Secure gateways, and consult the vendor advisory for the applicable fixed release since no version range is provided here. Where patching is not immediate, restrict HTTPS access to the appliance and hunt for signs of exploitation (unexpected file reads, anomalous VPN logins or sessions, and follow-on ransomware activity), as CISA reports known ransomware use.

10.0100% KEV ransomware PoC ×2
  • Ivanti Pulse Connect Secure
largeTens of thousands of internet-exposed gateways (order of 10,000-100,000 systems; each typically serves hundreds of VPN users, so potentially millions of users)
CVE-2019-19781
Unauthenticated path traversal RCE in Citrix ADC, Gateway, and SD-WAN WANOP

CVE-2019-19781 is a path-traversal flaw (classified CWE-22, though CISA's description calls it unspecified) in Citrix ADC (formerly NetScaler ADC), Citrix Gateway, and Citrix SD-WAN WANOP appliances that lets an unauthenticated remote attacker traverse directories via crafted requests and execute arbitrary commands on the appliance, typically with root privileges. It is triggered by sending specially crafted directory-traversal requests (crafted URLs/requests to the appliance's management or VPN endpoints), which lets the attacker write files and run commands with no credentials. Successful exploitation yields arbitrary code execution on the appliance, enabling theft of VPN/ADC credentials, lateral movement into the corporate network, and installation of persistent backdoors. Any organization running affected ADC, Gateway, or SD-WAN WANOP firmware is affected, with internet-facing gateways used for remote access at the highest risk. Exploitation is confirmed in the wild: the vulnerability is on CISA's KEV (added 2021-11-03) with known ransomware use, EPSS assigns near-certain (100.0%) probability of exploitation within 30 days, and no public PoC is listed despite confirmed abuse.

Do: Upgrade Citrix ADC, Gateway, and SD-WAN WANOP appliances to the fixed firmware builds listed in Citrix advisory CTX267020; if patching cannot be done immediately, apply Citrix's published interim mitigation and restrict internet exposure to the appliance. Because exploitation grants root code execution and persistence, after patching hunt for indicators of compromise (unexpected nsroot account, modified system files, crontab/scheduled entries), kill all active and inactive sessions, and rotate appliance and VPN credentials. Prioritize internet-facing gateways and comply with CISA's required action to apply vendor updates.

9.8100% KEV ransomware
  • Citrix Application Delivery Controller (ADC) Supported ADC firmware lines in effect at disclosure (10.5, 11.0, 11.1, 12.0, 12.1, 13.0) prior to patched builds, per Citrix advisory CTX267020; exact builds n
  • Citrix Gateway Supported Gateway firmware lines (sharing the ADC codebase, same affected releases 10.5-13.0) prior to patched builds, per Citrix advisory; exact builds not spe
  • Citrix SD-WAN WANOP Appliance Affected appliance models (4000, 4100, 5000, 5100) running pre-patch firmware in the 10.2.1-11.4.1 range, per Citrix advisory; exact builds not specified in the
massroughly 80,000-100,000+ internet-exposed Citrix ADC/Gateway appliances at the time of disclosure, with a far larger total installed base (including…
CVE-2020-15505
Unauthenticated Hessian Java Deserialization RCE in Ivanti MobileIron

CVE-2020-15505 is a critical, unauthenticated remote code execution vulnerability in Ivanti MobileIron's Core and Enterprise Connector, Sentry, and Monitor and Reporting Database (RDB) products, which public proof-of-concept exploits identify as a Hessian-based Java deserialization flaw. An unauthenticated attacker can send crafted requests to an affected MobileIron server over the network, with no privileges or user interaction required, and execute arbitrary code, gaining full control of the MDM server with high impact on confidentiality, integrity, and availability. Any organization running the affected versions of these enterprise mobile device management products is at risk, particularly internet-facing MobileIron Core and Sentry instances. Exploitation is confirmed and widespread: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added November 3, 2021), carries a 99.7% EPSS score, and was named among the top flaws exploited by Chinese state-sponsored hackers, prompting urgent UK NCSC patching alerts. It is also being observed chained with other exploited vulnerabilities (e.g., VPN flaws and Zerologon) as an initial-access vector, so defenders should treat it as actively exploited.

Do: Apply the vendor updates immediately per Ivanti's security advisory for MobileIron Core, Enterprise Connector, Sentry, and RDB (this is CISA's required action for KEV entries). Until patched, reduce internet exposure of MobileIron interfaces and monitor for exploitation; because the flaw was mass-exploited (including by Chinese state-sponsored actors), hunt for signs of compromise such as unexpected processes, persistence mechanisms, or webshells on affected MDM servers.

9.8100% KEV PoC ×2
  • Ivanti (MobileIron) MobileIron Core 10.3.0.3 and earlier; 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3; 10.5.1.0, 10.5.2.0; 10.6.0.0
  • Ivanti (MobileIron) Enterprise Connector 10.3.0.3 and earlier; 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3; 10.5.1.0, 10.5.2.0; 10.6.0.0 (same version set as Core)
  • Ivanti (MobileIron) Sentry 9.7.2 and earlier; 9.8.0
  • +1 more
largeon the order of 10,000+ internet-exposed MobileIron servers, reaching millions of managed endpoints through enterprise MDM deployments (estimate)
CVE-2020-1631
Unauthenticated Path Traversal/LFI in Juniper Junos OS HTTP/HTTPS Service

CVE-2020-1631 is a path traversal and local file inclusion flaw in the HTTP/HTTPS service (httpd) used by J-Web, Web Authentication, Dynamic-VPN, Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning in Juniper Junos OS. An unauthenticated network attacker sends crafted requests to any enabled HTTP/HTTPS service and can inject commands into httpd.log (limited, since the service runs as user 'nobody'), read world-readable files—including the device configuration file on Junos 19.3R1 and above—or obtain J-Web session tokens. If J-Web is enabled, the attacker can hijack an active session and inherit that user's access, gaining administrator privileges to J-Web if an administrator is logged in (up to CVSS 8.8; the dashboard rates the worst case 9.8). Only Junos devices with HTTP/HTTPS services enabled are affected; the advisory's version range begins with Junos OS 12.3 prior to 12.3R12 (the source text is truncated). Juniper SIRT received a single report of exploitation in the wild, the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), and EPSS estimates a 4.7% chance of exploitation in the next 30 days (91st percentile).

Do: Upgrade Junos OS per Juniper's advisory (at minimum past the 12.3R12 boundary given in the affected range; consult Juniper for fixed releases on other branches). As mitigation, disable J-Web/HTTP(S) management services where not needed or restrict access with firewall filters/ACLs. Hunt for compromise by searching /var/log/httpd.log (and rotated httpd.log.0.gz/.1.gz) for the patterns "=*;*&" or "=*%3b*&", keeping in mind a skilled attacker may have removed these entries.

9.85% KEV
  • Juniper Networks Junos OS 12.3 versions prior to 12.3R12 (advisory version list truncated in source; only devices with HTTP/HTTPS services enabled are affected; config-file exposure note
largetens of thousands of internet-exposed Junos devices with HTTP/HTTPS (J-Web or related web services) enabled
CVE-2020-2021
SAML Authentication Bypass in Palo Alto Networks PAN-OS

CVE-2020-2021 is an improper signature-verification flaw (CWE-347) in PAN-OS SAML authentication that lets an unauthenticated network-based attacker bypass identity verification when SAML is enabled and the 'Validate Identity Provider Certificate' option is left unchecked. An attacker with network access to a vulnerable GlobalProtect gateway or portal, GlobalProtect Clientless VPN, Captive Portal, or Prisma Access can gain access to protected resources permitted by the configured authentication and security policies, without affecting session integrity or availability for regular users. If SAML is used to protect the PAN-OS or Panorama web interfaces, the attacker can log in as an administrator and perform administrative actions, making this a worst-case CVSS 10.0 (critical) issue. Affected deployments run PAN-OS 9.1 before 9.1.3, 9.0 before 9.0.9, 8.1 before 8.1.15, or any 8.0 release (end-of-life); PAN-OS 7.1 is not affected, and the flaw cannot be exploited where SAML is unused or certificate validation is enabled. The vendor reported no malicious exploitation at disclosure, but the flaw has since been added to CISA's Known Exploited Vulnerabilities catalog (March 2022) with known ransomware use, and headlines tie it to foreign espionage and APT activity chaining VPN flaws.

Do: Upgrade to PAN-OS 9.1.3, 9.0.9, or 8.1.15 or later as applicable, and migrate off EOL PAN-OS 8.0; PAN-OS 7.1 requires no action. As an immediate mitigation, enable (check) the 'Validate Identity Provider Certificate' option in the SAML Identity Provider Server Profile. Restrict the PAN-OS and Panorama web interfaces to a trusted management network and audit whether SAML is used for GlobalProtect, Captive Portal, Prisma Access, or administrator authentication to confirm exposure.

10.04% KEV ransomware
  • Palo Alto Networks PAN-OS 9.1 versions earlier than 9.1.3; 9.0 versions earlier than 9.0.9; 8.1 versions earlier than 8.1.15; all PAN-OS 8.0 versions (EOL); PAN-OS 7.1 not affected
largetens of thousands of internet-exposed PAN-OS firewalls, gateways and management interfaces, of an installed base of hundreds of thousands
Full article384 words · extracted from infosecurity-magazine.com · click to collapse

Security vendor SonicWall has warned its customers that threat actors may have found zero-day vulnerabilities in some of its remote access products.

An initial post on the vendor’s knowledgebase pages on Friday claimed that the NetExtender VPN client version 10.x and the SMB-focused SMA 100 series were at risk.

However, an update over the weekend clarified that impacted products were confined to its Secure Mobile Access (SMA) version 10.x offering running on SMA 200, SMA 210, SMA 400, SMA 410 physical appliances and the SMA 500v virtual appliance.

These provide customer employees with secure remote access to internal resources — capabilities in high demand during the pandemic. As such, there’s an obvious advantage to attackers in finding bugs to exploit in such tools.

“We believe it is extremely important to be transparent with our customers, our partners and the broader cybersecurity community about the ongoing attacks on global business and government,” SonicWall said in the alert.

“Recently, SonicWall identified a coordinated attack on its internal systems by highly sophisticated threat actors exploiting probable zero-day vulnerabilities on certain SonicWall secure remote access products.”

There’s no more info for now on what the attackers were after and how they performed the intrusion.

However, SonicWall also clarified that its firewall products, SonicWave APs and SMA 1000 Series product line are unaffected.

“Current SMA 100 Series customers may continue to use NetExtender for remote access with the SMA 100 series. We have determined that this use case is not susceptible to exploitation,” it added. “We advise SMA 100 series administrators to create specific access rules or disable Virtual Office and HTTPS administrative access from the internet while we continue to investigate the vulnerability.”

Since the start of the COVID-19 crisis, security and infrastructure providers have come under increasing scrutiny as attackers look for holes in products which could provide them with large-scale access to customer environments.

Back in April, it emerged that sophisticated ransomware groups were exploiting flaws in VPN products to attack hospitals, while in October, the US warned that APT groups were chaining VPN exploits with the Zerologon flaw to target public and private sector organizations.

Products from Fortinet (CVE-2018-13379), MobileIron (CVE-2020-15505), Juniper (CVE-2020-1631), Pulse Secure (CVE-2019-11510), Citrix NetScaler (CVE-2019-19781) and Palo Alto Networks (CVE-2020-2021) were all highlighted as at risk.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/sonicwall-probes-zerodays-in-own/