CISA Adds Critical RocketMQ Bug to Must
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-33246 | Unauthenticated Remote Command Execution in Apache RocketMQ CVE-2023-33246 is an unauthenticated remote command execution flaw in Apache RocketMQ: when NameServer, Broker, or Controller components are exposed without access controls, an attacker can invoke the update-configuration function or forge RocketMQ protocol messages to inject and run operating-system commands. Commands execute with the privileges of the system user running RocketMQ, giving an attacker full control of the message broker host. Any organization running RocketMQ 5.1.0 or below (5.x) or versions below 4.9.6 (4.x) with these components reachable by untrusted networks is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-06, carries a 96.6% EPSS probability of exploitation, has multiple public PoC exploits, and is being leveraged by the Muhstik botnet to expand DDoS operations alongside other malware campaigns. Do: Upgrade to RocketMQ 5.1.1 or above for 5.x deployments, or 4.9.6 or above for 4.x, per the KEV required action. Until patched, restrict NameServer, Broker, and Controller ports to trusted clients only and avoid exposing them to the internet without authentication or access filtering. Check patched hosts for signs of compromise (unauthorized processes, cron jobs, or botnet activity such as Muhstik), since active exploitation is documented. | 9.8 | 97% | KEV PoC ×4 |
| largeTens of thousands of internet-exposed instances plausible (thousands confirmed in public scans; total installed base larger, exact count unknown) |
Full article286 words · extracted from infosecurity-magazine.com · click to collapse
The US government has ordered all federal civilian agencies to patch a critical vulnerability in Apache RocketMQ, which is currently being exploited in the wild.
The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2023-33246 to its Known Exploited Vulnerabilities Catalog. It means government agencies have until September 27 to apply a vendor patch to affected systems, although private enterprises are encouraged to follow suit.
The bug affects versions 5.1.0 and below of the popular distributed messaging and streaming platform. It has been given a CVSS rating of 9.8.
“Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as,” explained NIST in an advisory.
“Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content. To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x.”
Read more on known exploited vulnerabilities: CISA: Patch Bug Exploited by Chinese E-commerce App
Last month, Juniper Networks reported that the remote code execution vulnerability was being exploited in a “series of attacks” that date back to June. The software flaw was publicly disclosed in May.
The security and networking vendor said it detected several of these campaigns exploiting CVE-2023-33246 to install the DreamBus bot for Monero cryptocurrency mining.
Threat intelligence firm VulnCheck said it used Censys to detect around 4500 potentially exposed Apache RocketMQ systems.
“However, the extreme concentration of systems in one country does call into question how many of these may be honeypots,” it added.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-critical-rocketmq-bug/