ZeroHour
Ars Technica · Securitypublished ()ingested

Nation-state hackers exploit Cisco firewall 0

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-20353
+1 in the same advisory: …20359
Unauthenticated Device-Reload DoS in Cisco ASA and FTD Web Servers

CVE-2024-20353 is a denial-of-service flaw in the management and VPN web servers of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software, caused by incomplete error checking when parsing an HTTP header (tracked as CWE-835, a loop-exit defect). An unauthenticated, remote attacker can trigger it by sending a crafted HTTP request to the device's web server, causing the firewall/VPN appliance to reload unexpectedly. A successful exploit yields no data theft from the flaw itself but takes the device offline, and repeated requests can sustain an outage of the edge firewall and VPN service. Any organization running ASA or FTD with these web servers reachable by attackers is exposed, which includes nearly every internet-facing Cisco edge deployment. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-24, is referenced in a public Cisco Talos writeup on the ArcaneDoor campaign, where suspected state-sponsored (China-linked) actors chained it with CVE-2024-20359 to backdoor ASA perimeter devices, and EPSS assigns it a 70.7% probability of exploitation within 30 days (99th percentile).

Do: Upgrade ASA and FTD to the fixed releases listed in Cisco's security advisory (version ranges not included in this data), and because attackers in the ArcaneDoor campaign may have persisted on devices via the related CVE-2024-20359 backdoor, check for unexpected configuration changes or persistence before and after patching. Restrict exposure of the ASA/FTD management and VPN web servers to trusted source addresses while remediation is pending. Per CISA's KEV required action, apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

8.6
group max
71% KEV PoC
  • Cisco Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
massseveral hundred thousand internet-exposed Cisco ASA/FTD appliances worldwide
Full article341 words · extracted from arstechnica.com · click to collapse

Those characteristics, combined with a small cast of selected targets all in government, have led Talos to assess that the attacks are the work of government-backed hackers motivated by espionage objectives.

“Our attribution assessment is based on the victimology, the significant level of tradecraft employed in terms of capability development and anti-forensic measures, and the identification and subsequent chaining together of 0-day vulnerabilities,” Talos researchers wrote. “For these reasons, we assess with high confidence that these actions were performed by a state-sponsored actor.”

The researchers also warned that the hacking campaign is likely targeting other devices besides the ASA. Notably, the researchers said they still don’t know how UAT4356 gained initial access, meaning the ASA vulnerabilities could be exploited only after one or more other currently unknown vulnerabilities—likely in network wares from Microsoft and others—were exploited.

“Regardless of your network equipment provider, now is the time to ensure that the devices are properly patched, logging to a central, secure location, and configured to have strong, multi-factor authentication (MFA),” the researchers wrote. Cisco has released security updates that patch the vulnerabilities and is urging all ASA users to install them promptly.

UAT4356 started work on the campaign no later than last July when it was developing and testing the exploits. By November, the threat group first set up the dedicated server infrastructure for the attacks, which began in earnest in January. The following image details the timeline:

Credit: Cisco

Credit: Cisco

One of the vulnerabilities, tracked as CVE-2024-20359, resides in a now-retired capability allowing for the preloading of VPN clients and plug-ins in ASA. It stems from improper validation of files when they’re read from the flash memory of a vulnerable device and allows for remote code execution with root system privileges when exploited. UAT4356 is exploiting it to backdoors Cisco tracks under the names Line Dancer and Line Runner. In at least one case, the threat actor is installing the backdoors by exploiting CVE-2024-20353, a separate ASA vulnerability with a severity rating of 8.6 out of a possible 10.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2024/04/cisco-firewall-0-days-under-attack-for-5-months-by-resourceful-nation-state-hackers/