ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA ADDS ANDROID PIXEL AND SUNHILLO SURELINE BUGS TO ITS KNOWN EXPLOITED VULNERABILITIES CATALOG

highExploit / PoC exploited in the wildimportance 60CVE-2023-21237CVE-2021-36380

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-36380
Unauthenticated OS Command Injection in Sunhillo SureLine

Sunhillo SureLine before version 8.7.0.1.1 contains an unauthenticated OS command injection flaw (CWE-78) in its /cgi/networkDiag.cgi web endpoint. An attacker with network access to the device's management interface can inject shell metacharacters into the ipAddr or dnsAddr parameters, causing arbitrary operating system commands to be executed with the privileges of the web service. Because no authentication or user interaction is required (CVSS 3.1: 9.8, AV:N/AC:L/PR:N/UI:N), a remote attacker can achieve full command execution, with high impact on confidentiality, integrity, and availability of the device. SureLine is Sunhillo's surveillance data distribution platform used primarily in the aviation sector (airports and air traffic control facilities), so affected users are mainly those organizations rather than the general public. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on 2024-03-05, indicating it has been observed being exploited in the wild, and a public technical advisory with a proof of concept was published by NCC Group in July 2021.

Do: Upgrade SureLine to version 8.7.0.1.1 or later. If upgrading is not immediately possible, restrict network access to the device's management interface (especially the /cgi/networkDiag.cgi endpoint) and place the unit behind a firewall or VPN rather than exposing it directly to the internet. Note that as a KEV-listed vulnerability, CISA requires applying vendor mitigations or discontinuing use of the product, so inventory any internet-exposed SureLine appliances and check logs for unexpected requests to networkDiag.cgi.

9.898% KEV PoC
  • Sunhillo SureLine All versions before 8.7.0.1.1
nichelikely hundreds to a few thousand deployments worldwide, concentrated in the aviation sector (unknown exact count)
CVE-2023-21237
Information Disclosure via Hidden Foreground Service Notifications on Android 13 Pixels

CVE-2023-21237 is an information disclosure flaw (CWE-200) in the applyRemoteView function of NotificationContentInflater.java on Android 13, where misleading or insufficient UI can cause a foreground service notification to be hidden from the user. A locally installed app with only low privileges can trigger the condition without any user interaction, causing the system not to visibly display the app's foreground service notification. An attacker gains a covert execution context: the user receives no indication that an app or service is running, which Google classifies as local information disclosure because the user is deprived of awareness of activity on their device. Affected users are those with Google Pixel devices running Android 13, per CISA's advisory. The bug was added to CISA's Known Exploited Vulnerabilities catalog on 2024-03-05, confirming in-the-wild exploitation, though EPSS currently estimates only a 0.3% probability of exploitation in the next 30 days and no public PoC is known.

Do: Apply Google's latest Pixel/Android monthly security update to all Android 13 Pixel devices, prioritizing fleet patching per the CISA KEV required action, and verify devices report a security patch level that includes this fix. As a detection aid, review installed apps that run foreground services whose notifications are not visible, since hiding the foreground service notification is the core abuse of this flaw. If patching is not possible, follow vendor mitigations per CISA guidance or discontinue use of affected devices.

5.5<1% KEV
  • Google Android (Pixel devices)
massmillions of Pixel devices running Android 13 (a subset of Google's estimated tens-of-millions cumulative Pixel install base)
Full article266 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Android Pixel and Sunhillo SureLine vulnerabilities to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

The Android Pixel vulnerability, tracked as CVE-2023-21237, resides in applyRemoteView of NotificationContentInflater.java. The exploitation of this vulnerability could lead to local information disclosure with no additional execution privileges needed. The exploitation doesn’t require user interaction.

Google addressed the issue in June 2023, the IT giant is aware of “limited, targeted exploitation.”

“There are indications that CVE-2023-21237 may be under limited, targeted exploitation.” reads the security bulletin published by the company.

The issue is likely chained with other flaws in an exploit used by a commercial spyware vendor or a nation-state actor.

The second issue added to the Catalog is an OS Command Injection vulnerability in Sunhillo SureLine. The exploitation of the flaw can allow to execute arbitrary commands with root privileges.

The exploitation can lead to complete system compromise.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by March 26, 2024.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – ransomware, CISA



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/160081/security/cisa-android-pixel-sunhillo-sureline-bugs-known-exploited-vulnerabilities-catalog.html