ZeroHour
The Recordpublished ()ingested

FileWave patches two vulnerabilities that impacted more than 1,000 orgs

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-1388
Unauthenticated RCE in F5 BIG-IP via Missing Authentication

F5 BIG-IP contains a critical missing-authentication flaw (CWE-306) in its iControl REST control plane: an unauthenticated attacker with network reachability to the management interface, or to self IPs exposing the REST service on TCP 443, can bypass authentication completely. By sending specially crafted HTTP requests, the attacker gains the ability to execute arbitrary code, create or delete files, and disable services, effectively achieving full takeover of the load balancer or security appliance and the traffic it handles. All F5 BIG-IP deployments running unpatched software are affected; the provided data does not enumerate exact version ranges, which are listed in F5's May 2022 security advisory. The flaw was added to CISA's KEV catalog on 2022-05-10 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), indicating active in-the-wild exploitation. No public proof-of-concept is catalogued in the provided data, but the KEV listing and known ransomware use confirm real-world attacks.

Do: Upgrade affected F5 BIG-IP systems to the fixed releases listed in F5's May 2022 security advisory (K23605340) immediately, prioritizing appliances whose management interface or self IPs on TCP 443 are reachable from untrusted networks; as an interim mitigation, block untrusted access to the management interface and the iControl REST service. Because this flaw is in CISA's KEV catalog with known ransomware use, also hunt for signs of compromise (unexpected files, disabled services, unknown persistence) on any system that was exposed before patching.

9.8100% KEV ransomware PoC ×4
  • F5 BIG-IP
large~10,000 internet-exposed BIG-IP systems (public scans at disclosure counted 8k-10k+), with a far larger installed base behind firewalls
CVE-2022-34907
+1 in the same advisory: …34906
An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2.

An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform.

NVD description · AI analysis pending
9.8
group max
16% PoC
  • filewave filewave
Full article632 words · extracted from therecord.media · click to collapse

Swiss device management company FileWave confirmed on Tuesday that two vulnerabilities in their platform have been patched after being discovered by researchers from Claroty’s Team82.

The vulnerabilities – CVE-2022-34907 and CVE-2022-34906 – were found in FileWave’s mobile device management (MDM) system and affect thousands of companies that use the system. 

Noam Mosche, a researcher for Claroty’s Team82, told The Record that it is common for any type of organization to use an MDM solution considering the large number of IoT devices in use today. The tools make it simpler for IT administrators to manage all of an organization’s devices effectively. 

“In our research we discovered more than 1,100 FileWave MDM instances across multiple organizations, including large corporations, schools and educational institutions, government agencies, and small and medium businesses,” Mosche said. 

FileWave’s MDM system allows IT departments to manage, monitor, and view all of an organization’s devices, ranging from iOS and Android smartphones, MacOS and Windows tablets to laptops and workstations, and smart devices such as televisions.

The vulnerabilities are remotely exploitable and allow an attacker to bypass authentication mechanisms and gain full control over the MDM platform and its managed devices. 

CVE-2022-34907 is an authentication bypass flaw that exists in FileWave MDM before version 14.6.3 and 14.7.x, prior to 14.7.2. CVE-2022-34906, a hard-coded cryptographic key, exists in FileWave MDM prior to version 14.6.3 and 14.7.x, prior to 14.7.2.

Mosche compared the vulnerability to one that was recently discovered in F5 BIG-IP devices (CVE-2022-1388), which he said “caused a lot of headaches for many IT administrators.” 

“Authentication bypass vulnerabilities, such as CVE-2022-34907, are unfortunately more common than many people realize,” Mosche said. 

Claroty also compared the vulnerabilities to ones used by the REvil ransomware group during the headline-grabbing attack on Kaseya in July 2021 that spread ransomware to more than 1,500 organizations around the world. 

“Furthermore, attackers could abuse legitimate MDM capabilities to install malicious packages or executables, and even gain access to the device directly through remote control protocols,” Claroty explained in its report. 

A Claroty graph of the issue.

Management services like this provide attackers with wide-ranging control over an organization. Claroty said a hacker could use CVE-2022-34907 to not only take over all managed devices but also exfiltrate sensitive data like device serial numbers, user email addresses, geo-location coordinates, IP addresses, device PIN codes and more. 

FileWave addressed the vulnerabilities in a recent update, according to a statement sent to The Record.  

The security update released to address the vulnerabilities is included in the patched software upgrades of versions 14.6.3, 14.7.2, as well as in the latest software release 14.8, and all future subsequent versions, FileWave explained. 

FileWave said it is not aware of any exploitation of the vulnerability, but recommended users to “double-check that the security update is properly installed and up to date to avoid the risk of third-party attacks going forward.”

The spokesperson added that all affected software users were first notified of the vulnerabilities by FileWave on 26th April 2022 and were provided with a software upgrade to address the vulnerabilities. 

“The security vulnerabilities were carefully reviewed and confirmed in close cooperation with Claroty Research,” the company said. 

“Immediately after the vulnerabilities became known, measures were taken to develop patched versions of the software, following a robust protocol to not only provide FileWave software users with a solution, but also to protect and help them understand the risks and install software upgrades on their servers in a timely manner.”

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/filewave-patches-two-vulnerabilities-that-impacted-more-than-1000-orgs