ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA warns that Pulse Secure VPN issue CVE-2019

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-13379
Unauthenticated Path Traversal in Fortinet FortiOS SSL VPN

CVE-2018-13379 is a path traversal flaw (CWE-22) in the Fortinet FortiOS SSL VPN web portal that allows an unauthenticated attacker to download FortiOS system files via specially crafted HTTP resource requests. By traversing directories through crafted requests to the exposed web portal, the attacker can retrieve sensitive files, a technique publicly documented as yielding the SSL VPN session file containing usernames and passwords in plaintext. Any organization running the SSL VPN web portal on a FortiGate appliance is affected, and risk is highest where the portal is directly reachable from the internet. The flaw is confirmed in the wild: it was added to the CISA KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. No public PoC is listed in the provided data, but credential theft tied to this bug has been widely reused by threat actors.

Do: Apply the patched FortiOS release per Fortinet's vendor advisory immediately, as this is a CISA KEV required action; if the fixed version is not known from this data, follow Fortinet's FG-IR-18-384 advisory for the correct upgrade path. Rotate SSL VPN credentials and review VPN access logs for path-traversal requests, since successful exploitation exposes plaintext session credentials, and restrict SSL VPN portal exposure to trusted sources where possible.

9.8100% KEV ransomware
  • Fortinet FortiOS
mass≈500,000 internet-exposed FortiOS SSL VPN portals (Fortinet cited ~480,000 affected devices)
CVE-2019-11510
Unauthenticated Arbitrary File Read in Ivanti Pulse Connect Secure VPN

Ivanti Pulse Connect Secure, an enterprise SSL VPN appliance, contains an arbitrary file read vulnerability (CWE-22, path traversal) that requires no authentication. An unauthenticated remote attacker with network access to the appliance over HTTPS can send a specially crafted URI containing traversal sequences to read arbitrary files from the device. The attacker gains access to sensitive appliance files, potentially including configuration or credential material useful for further compromise, and CISA records known ransomware use of this flaw. Any organization running Pulse Connect Secure, especially gateways exposed to the internet for remote access, is affected. Exploitation is established: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a 100% probability of exploitation in the next 30 days, and no public PoC is known.

Do: Apply updates per Ivanti's instructions, the required action in the CISA KEV entry, prioritizing internet-facing Pulse Connect Secure gateways, and consult the vendor advisory for the applicable fixed release since no version range is provided here. Where patching is not immediate, restrict HTTPS access to the appliance and hunt for signs of exploitation (unexpected file reads, anomalous VPN logins or sessions, and follow-on ransomware activity), as CISA reports known ransomware use.

10.0100% KEV ransomware PoC ×2
  • Ivanti Pulse Connect Secure
largeTens of thousands of internet-exposed gateways (order of 10,000-100,000 systems; each typically serves hundreds of VPN users, so potentially millions of users)
CVE-2019-11539
Authenticated Command Injection in Ivanti Pulse Connect Secure and Policy Secure

Ivanti/Pulse Secure Pulse Connect Secure and Pulse Policy Secure contain an OS command injection flaw (CWE-78) in the admin web interface. An authenticated attacker can send crafted requests to the administrative web interface to inject and execute arbitrary operating-system commands on the appliance. Successful exploitation gives full control of the VPN or network access control appliance, enabling data theft, persistence, and pivoting into the corporate intranet. Any organization running an affected Pulse Connect Secure (9.0RX/8.3RX/8.2RX/8.1RX) or Pulse Policy Secure (9.0RX/5.4RX/5.3RX/5.2RX/5.1RX) release is exposed, especially internet-facing VPN gateways. Exploitation is very active: the bug is in CISA's KEV, public research chained it with CVE-2019-11510 into an unauthenticated RCE chain, APT groups and Black Kingdom ransomware operators have been reported exploiting Pulse VPN flaws, and EPSS estimates a 98.5% probability of exploitation within 30 days.

Do: Upgrade Pulse Connect Secure to 9.0R3.4+ (or 8.3R7.1+, 8.2R12.1+, 8.1R15.1+) and Pulse Policy Secure/Policy Secure to 9.0R3.2+ (or 5.4R7.1+, 5.3R12.1+, 5.2R12.1+, 5.1R15.1+) per vendor instructions. Restrict exposure of the admin web interface to trusted networks, rotate administrative credentials, and hunt for signs of compromise on appliances that were internet-exposed, particularly where the chained CVE-2019-11510 file-read flaw may also have been exploited.

7.299% KEV ransomware PoC ×2
  • ivanti / pulsesecure Pulse Connect Secure 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, 8.1RX before 8.1R15.1
  • ivanti / pulsesecure Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, 5.1RX before 5.1R15.1
  • ivanti / pulsesecure Policy Secure Same ranges as Pulse Policy Secure (9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, 5.1RX before 5.1R15.1)
masson the order of 100,000 to several hundred thousand internet-exposed Pulse Connect Secure/Policy Secure appliances
Full article455 words · extracted from securityaffairs.com · click to collapse

The US DHS CISA agency is warning organizations that threat actors continue to exploit the CVE-2019-11510 Pulse Secure VPN vulnerability.

The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations that attackers continue to exploit the well known Pulse Secure VPN vulnerability tracked as CVE-2019-11510.

The CVE-2019-11510 flaw in Pulse Connect Secure is a critical arbitrary file read vulnerability.

“Unauthenticated remote attacker with network access via HTTPS can send a specially crafted URI to perform an arbitrary file reading vulnerability.” reads the advisory.

The vulnerability could be easily exploitable by using publicly available proof-of-concept code. The flaw can be used in combination with the CVE-2019-11539 remote command injection issue gain access to private VPN networks.

Recently the popular cybersecurity researcher Kevin Beaumont reported that he was informed of attacks exploiting the Pulse Secure flaw to deliver a piece of the Sodinokibi ransomware.

Beaumont revealed that he had become aware of two notable incidents where attackers exploited the Pulse Secure flaws.

“In both cases the organisations had unpatched Pulse Secure systems, and the footprint was the same — access was gained to the network, domain admin was gained, VNC was used to move around the network (they actually installed VNC via psexec, as java.exe), and then endpoint security tools were disabled and Sodinokibi was pushed to all systems via psexec,” Beaumont explained in a blog post.

In October, the UK’s National Cyber Security Centre (NCSC) reported that advanced persistent threat (APT) groups have been exploiting recently disclosed VPN vulnerabilities in enterprise VPN products in attacks in the wild. Threat actors leverage VPN vulnerabilities in Fortinet, Palo Alto Networks and Pulse Secure, to breach into the target networks.

The UK agency reported that APT groups target several vulnerabilities, including CVE-2019-11510 and CVE-2019-11539 in Pulse Secure VPN solutions, and CVE-2018-13379.

NSA also warned of multiple state-sponsored cyberespionage groups exploiting enterprise VPN Flaws

Despite Pulse Secure addressed the flaw in April, thousands of Pulse Secure VPN endpoints are yet to be fixed.

In January 2020, Bad Packets reported that there were still 3,623 vulnerable Pulse Secure VPN servers, 1,233 of which were in the United States.

https://twitter.com/bad_packets/status/1215680652323897346

Now CISA agency confirmed that threat actors continue to exploit the CVE-2019-11510 flaw.

“Although Pulse Secure disclosed the vulnerability and provided software patches for the various affected products in April 2019, the Cybersecurity and Infrastructure Security Agency (CISA) continues to observe wide exploitation of CVE-2019-11510,” reads the alert published by CISA.

“CISA expects to see continued attacks exploiting unpatched Pulse Secure VPN environments and strongly urges users and administrators to upgrade to the corresponding fixes,”

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Pulse Secure VPN, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/96268/hacking/pulse-secure-vpn-cve-2019-11510.html