Ransomware groups targeting Mitel VoIP zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-29499 | Unauthenticated RCE in Mitel MiVoice Connect Service Appliance CVE-2022-29499 is an improper input-validation flaw (CWE-20) in the Service Appliance component (SA 100, SA 400, and Virtual SA) of Mitel MiVoice Connect, affecting releases through 19.2 SP3. A remote, unauthenticated attacker can trigger it by sending improperly validated data to the appliance over the network; the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no privileges, user interaction, or special conditions are required. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, giving the attacker a foothold on the appliance inside the organization's voice/UC environment. Any organization running a MiVoice Connect deployment that includes one of the Service Appliances is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-27 with known ransomware use, and press reports describe the Lorenz ransomware group and others exploiting this Mitel VoIP zero-day for initial access into business networks (EPSS: 55.6% chance of exploitation in 30 days). Do: Apply Mitel's update for the Service Appliance component per the vendor's instructions, since all releases up through 19.2 SP3 are affected; do not delay, as ransomware groups are actively exploiting the flaw for initial access. Identify whether your MiVoice Connect deployment includes an SA 100, SA 400, or Virtual SA, restrict the appliance's web interface from direct internet exposure until patched, and after updating check the appliance for signs of compromise or follow-on ransomware activity. | 9.8 | 56% | KEV ransomware |
| largeestimated tens of thousands of business deployments with thousands of internet-exposed Service Appliances (clearly an estimate) |
Full article465 words · extracted from therecord.media · click to collapse
Ransomware groups are targeting a zero-day affecting a Linux-based Mitel VoIP appliance, according to researchers from CrowdStrike. The zero-day – tagged as CVE-2022-29499 – was patched in April by Mitel after CrowdStrike researcher Patrick Bennett discovered the issue during a ransomware investigation. In a blog post on Thursday, Bennett explained that after taking the Mitel VoIP appliance offline, he discovered a “novel remote code execution exploit used by the threat actor to gain initial access to the environment.” “After tracing threat actor activity to an IP address assigned to the Mitel MiVoice Connect VoIP appliance, CrowdStrike received a disk image of the Linux system and began analysis. CrowdStrike’s analysis identified anti-forensic techniques that were performed by the threat actor on the Mitel appliance in an attempt to hide their activity,” Bennett said. “Although the threat actor deleted all files from the VoIP device’s filesystem, CrowdStrike was able to recover forensic data from the device. This included the initial undocumented exploit used to compromise the device, the tools subsequently downloaded by the threat actor to the device, and even evidence of specific anti-forensic measures taken by the threat actor.” In its security advisory, Mitel said the vulnerability affects the Mitel Service Appliance component of MiVoice Connect. The company rated the bug critical and said it could be exploited in MiVoice Connect Service Appliances, SA 100, SA 400 and/or Virtual SA. A script for remediation was provided to customers, according to Mitel. Cybersecurity expert Kevin Beaumont urged organizations to patch the vulnerability and noted that a search on Shodan showed several government institutions in the United States and United Kingdom were vulnerable to the bug. This is filtered to just ones with SSL certificates with ".gov*" in the hostname, there's a concentration in the UK (#1) and US (#2), so I think there probably needs to be messaging for orgs to get their houses in order, especially as it is under active exploitation before patch. pic.twitter.com/m8s4RGuuOW Bennett explained in his blog that even with timely patching, threat actors exploiting undocumented vulnerabilities is a persistent problem. Recorded Future ransomware expert Allan Liska said developing or buying exploits for commonly used external facing systems, such as Microsoft Exchange or Citrix, is expensive. “But, there are a lot of other Internet-facing systems that are not nearly as widely deployed and that has been where ransomware groups have focused their efforts,” Liska said. “This is a great example of that.”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/ransomware-groups-targeting-mitel-voip-zero-day