ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Sophos Web Appliance vulnerability exploited in the wild (CVE-2023-1671)

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-1671CVE-2020-2551

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-2551
Unauthenticated Remote Code Execution in Oracle WebLogic Server via IIOP

CVE-2020-2551 is a critical flaw in the WLS Core Components of Oracle WebLogic Server that allows an unauthenticated attacker with network access to the IIOP protocol to remotely compromise the server. An attacker sends crafted IIOP requests directly to a listening WebLogic instance and gains takeover of the server, with high impact to confidentiality, integrity, and availability (CVSS 9.8). Oracle WebLogic Server versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0 are affected, spanning widely deployed enterprise and government middleware environments. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-11-16, and EPSS assigns a 93.2% probability of exploitation within 30 days (100th percentile), indicating active and likely broad targeting. Because exploitation requires only network reachability to the IIOP listener and no credentials or user interaction, internet-exposed WebLogic servers are the primary targets.

Do: Apply the Oracle fixes for CVE-2020-2551 (October 2020 Critical Patch Update) to each affected WebLogic release, or move to a patched supported release per Oracle's instructions, consistent with CISA's KEV required action. Until patched, block or restrict IIOP traffic to WebLogic listeners (default port 7001) from untrusted networks and remove direct internet exposure of WebLogic admin and application servers. Review access logs for anomalous IIOP connections and check patched and unpatched hosts for signs of compromise.

9.893% KEV
  • Oracle WebLogic Server (Oracle Fusion Middleware, WLS Core Components) 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0
largeorder of 10,000–50,000 internet-exposed WebLogic instances (public internet-wide scans have repeatedly shown tens of thousands of hosts exposing WebLogic…
CVE-2023-1671
Command Injection RCE in Sophos Web Appliance Warn-Proceed Handler

Sophos Web Appliance contains a command injection flaw (CWE-77) in the handler that processes 'warn and proceed' requests from the appliance's block page, allowing untrusted input to reach a shell command. An attacker who can reach the warn-proceed endpoint sends a crafted request whose parameters inject arbitrary operating system commands, resulting in remote code execution on the appliance. Successful exploitation gives the attacker control of the appliance host, a foothold at the network perimeter, and a platform for follow-on actions such as credential theft or lateral movement. Any organization running Sophos Web Appliance, especially where the appliance's web interface or warning pages are reachable from the internet, is affected. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-16, and EPSS assigns it a 100% probability of exploitation in the next 30 days, though no public proof-of-concept is known.

Do: Update Sophos Web Appliance to the fixed release identified in Sophos's advisory and confirm the running build is patched; restrict access to the appliance's web interface to trusted networks and review access logs for suspicious requests to the warn-proceed endpoint. If mitigations are unavailable or the deployment is on an unsupported build, follow the CISA KEV required action and discontinue use of the product.

9.8100% KEV PoC
  • Sophos Web Appliance Affected version ranges not enumerated in source data; per the vendor advisory, releases prior to the patched build are vulnerable — apply the vendor's fixed re
moderate≈ low thousands of appliances (on-prem secure web gateway; public scans show only a few thousand internet-exposed instances)
Full article354 words · extracted from helpnetsecurity.com · click to collapse

CISA has added three vulnerabilities to its Known Exploited Vulnerabilities catalog, among them a critical vulnerability (CVE-2023-1671) in Sophos Web Appliance that has been patched by the company in April 2023.

About CVE-2023-1671

CVE-2023-1671 is a pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance that allows attackers to execute arbitrary code.

Sophos Web Appliance is a web gateway appliance that functions as a web proxy and scans potentially harmful content for numerous forms of malware.

The vulnerability was disclosed in early April by an external security researcher through the Sophos bug bounty program. It affected all versions of the appliances prior to version 4.3.10.4.

At the time, the company pushed out the update with the fix to all Sophos Web Appliance customers who haven’t switched off the “automatic update” setting (which is on by default). Sophos also advised customers to keep the device behind a firewall, i.e., to make sure it’s not accessible via the public internet.

The company also made sure to stress that Sophos Web Appliance would be reaching end of life on July 20, 2023, and would then stop receiving security or software updates. They urged organizations to switch to using Sophos Firewall.

CVE-2023-1671 exploited

A public PoC exploit for CVE-2023-1671 has been available since late April, and so has a script that could be used by defenders to scan for vulnerable devices on their network.

Still, it apparently took many months for attackers to try and leverage the flaw, most likely because the default automatic updating setting considerably reduced the potential pool of targets.

But now the Cybersecurity and Infrastructure Security Agency says it has evidence of active exploitation, though (as per usual) it didn’t offer more information than that.

Attackers often leverage older vulnerabilities

With vulnerability patching at organizations being, well, patchy, attackers still regularly exploit older vulnerabilities in their attacks.

In fact, one of the three vulnerabilities added by CISA to its KEV catalogue on Thursday is CVE-2020-2551, an unspecified bug in the Oracle WebLogic Server product of Oracle Fusion Middleware that has been reported by a researcher and patched way back in 2020.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/11/20/cve-2023-1671/