ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds Zoho, Apache, Qualcomm, Mikrotik flaws to the list of actively exploited issues

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-14847
Directory Traversal in MikroTik RouterOS Winbox Interface (Unauthenticated File Read)

CVE-2018-14847 is a directory traversal (CWE-22) vulnerability in the Winbox interface of MikroTik RouterOS through version 6.42. An unauthenticated remote attacker can send crafted Winbox requests that traverse directories to read arbitrary files on the device, while authenticated attackers can also write arbitrary files. By reading files an attacker can retrieve sensitive device data such as stored credentials or configuration, and file write capability can support further compromise of the router. Any MikroTik router or device running RouterOS at or below 6.42 with the Winbox interface reachable is affected, which includes large numbers of internet-exposed edge and ISP devices. The flaw is actively exploited: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-12-01), has multiple public PoCs, and compromised MikroTik routers have been used by threats such as Trickbot (as C2 proxies) and the Mēris botnet, with public scans reporting over 300,000 vulnerable devices.

Do: Apply MikroTik's updates per vendor instructions, moving RouterOS above version 6.42, prioritizing devices with Winbox reachable from untrusted networks. Until patched, restrict or disable Winbox access from WAN/untrusted interfaces to limit unauthenticated file reads. Given known botnet abuse of this flaw, check devices for signs of compromise and rotate credentials that may have been exposed via file reads.

9.196% KEV PoC ×7
  • mikrotik routeros through 6.42 (all versions at or below 6.42)
mass≈300,000+ internet-exposed MikroTik devices
CVE-2020-11261
Local Privilege Escalation via Memory Corruption in Qualcomm Snapdragon Chipsets

CVE-2020-11261 is an improper input validation flaw (CWE-20/CWE-787, resulting in memory corruption/out-of-bounds writes) in the memory-allocation handling of firmware across a wide range of Qualcomm Snapdragon chipsets. It is triggered when a user application requests a memory allocation of a huge size and the affected component fails to properly return an error; a local attacker — such as a malicious or compromised app already running on the device — can leverage this to escalate privileges. Successful exploitation yields elevated privileges with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, local attack vector, no user interaction required). Affected platforms span the Snapdragon Auto, Compute, Connectivity, Consumer IoT, Industrial IoT, Mobile, Voice & Music, and Wearables product lines, including widely deployed entry-level mobile SoCs and connectivity chips. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-12-01, confirming in-the-wild exploitation; it was quietly patched in Android security updates alongside related Arm and Qualcomm zero-days, no public PoC is known, and EPSS estimates a 1.8% probability of exploitation in the next 30 days.

Do: Apply updated Qualcomm firmware and driver packages per the vendor advisory, as required by CISA's KEV listing, and ensure Android devices receive the OEM security updates containing the fix. Inventory devices built on the listed chipsets (e.g., APQ8009, APQ8017, APQ8053, APQ8096AU) and confirm they run patched builds; there is no workaround beyond patching, since a local malicious app is sufficient to trigger the flaw.

7.82% KEV
  • Qualcomm APQ8009 firmware
  • Qualcomm APQ8009W firmware
  • Qualcomm APQ8017 firmware
  • +9 more
mass≈1 billion+ devices (affected Snapdragon SoC families ship in entry-level Android phones and IoT/automotive hardware at massive volume)
CVE-2021-37415
Authentication Bypass in Zoho ManageEngine ServiceDesk Plus REST API

CVE-2021-37415 is a missing-authentication flaw (CWE-306) in Zoho ManageEngine ServiceDesk Plus, an on-premises IT help desk and asset management platform. In builds before 11302, certain REST-API URLs can be reached without any authentication, so an unauthenticated attacker who can reach the service desk's HTTP interface can invoke those endpoints directly. Successful abuse grants access to whatever those REST endpoints expose, bypassing the product's normal login controls; CISA lists it on the Known Exploited Vulnerabilities catalog, and required action is applying vendor updates. Any organization running ServiceDesk Plus at a build earlier than 11302 is affected, with exposure concentrated on instances whose web/REST interfaces are reachable from the internet or untrusted networks. No public proof-of-concept is known, but CISA's KEV listing (added 2021-12-01) and an EPSS of 99.8% indicate active exploitation pressure.

Do: Upgrade ManageEngine ServiceDesk Plus to build 11302 or later per the vendor's instructions, as required by CISA's KEV listing. Until patched, restrict network access to the ServiceDesk Plus web/REST interfaces (reverse proxy, firewall, or VPN) and review access logs for unauthenticated requests to REST-API endpoints.

9.8100% KEV
  • Zoho ManageEngine ServiceDesk Plus (SDP) All builds before 11302
largetens of thousands of on-premises ServiceDesk Plus deployments, a subset internet-exposed
CVE-2021-40438
Server-Side Request Forgery (SSRF) in Apache HTTP Server mod_proxy

CVE-2021-40438 is a server-side request forgery flaw (CWE-918) in the mod_proxy module of Apache HTTP Server 2.4.48 and earlier. By sending a crafted request URI path, a remote attacker can cause the server to forward the request to an origin server chosen by the attacker instead of the intended backend. This lets the attacker use the web server as a proxy to reach internal network services, probe internal hosts, and bypass network access controls. Anyone running an affected Apache HTTP Server version with mod_proxy enabled in a proxying configuration is affected. The flaw is being actively exploited in the wild - it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-12-01 with known ransomware use - and EPSS assigns it the highest probability of near-term exploitation.

Do: Upgrade Apache HTTP Server to a release newer than 2.4.48 per vendor instructions. As an interim mitigation, restrict mod_proxy so it forwards only to explicitly configured backends (avoiding attacker-controlled origin selection) or disable mod_proxy where it is not required, and audit internet-facing Apache servers for proxy configurations. Because this flaw is on the CISA KEV list with known ransomware use, prioritize patching internet-facing systems immediately.

9.0100% KEV ransomware
  • Apache HTTP Server 2.4.48 and earlier
masshundreds of thousands of internet-facing Apache HTTP Server instances (only the mod_proxy-enabled subset is vulnerable)
CVE-2021-44077
Unauthenticated RCE in Zoho ManageEngine ServiceDesk Plus and SupportCenter Plus

CVE-2021-44077 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus, rooted in missing authentication (CWE-306) on /RestAPI servlet URLs, specifically the ImportTechnicians action in the Struts configuration. A remote attacker can trigger it by sending crafted unauthenticated requests to the RestAPI endpoints, requiring no credentials or user interaction. Successful exploitation yields arbitrary code execution in the context of the application, giving attackers full control of the help desk server as a foothold for further network compromise. Any organization running affected versions before ServiceDesk Plus 11306, ServiceDesk Plus MSP 10530, or SupportCenter Plus 11014 is affected, particularly where the console is internet-facing. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-12-01, carries a 93.3% EPSS probability of near-term exploitation, and headlines point to active APT campaigns and mass exploitation against ManageEngine ServiceDesk deployments.

Do: Upgrade to the fixed releases: ServiceDesk Plus 11306 or later, ServiceDesk Plus MSP 10530 or later, and SupportCenter Plus 11014 or later, per vendor instructions (CISA KEV requires this action). Until patched, restrict or firewall internet access to /RestAPI endpoints, and review access logs for unauthenticated requests to the ImportTechnicians action along with unexpected processes, files, or webshells on the server. Given the 93.3% EPSS score, active APT exploitation, and concurrent zero-day activity against other ManageEngine products, treat exposed instances as potentially compromised and hunt for post-exploitation activity.

9.893% KEV PoC
  • zohocorp ManageEngine ServiceDesk Plus all versions before 11306
  • zohocorp ManageEngine ServiceDesk Plus MSP all versions before 10530
  • zohocorp ManageEngine SupportCenter Plus all versions before 11014
largetens of thousands of on-prem help desk deployments worldwide, with thousands of instances directly internet-exposed (estimate)
Full article330 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 02, 2021

U.S. CISA urges to address vulnerabilities Qualcomm, Mikrotik, Zoho and the Apache Software Foundation software.

U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its catalog of actively exploited vulnerabilities recommending federal agencies to address the flaws in Qualcomm, Mikrotik, Zoho and the Apache Software Foundation software within specific timeframes and deadlines.

CISA also warns of risk to the federal enterprise for delaying to address these vulnerabilities.

The US Agency requests the Federal agencies to apply security patches for Zoho ManageEngine ServiceDesk flaws by December 15, 2021. The two flaws added to the catalog are the CVE-2021-37415 Zoho ManageEngine ServiceDesk authentication bypass vulnerability and the CVE-2021-44077 Zoho ManageEngine ServiceDesk Plus remote code execution.

Both issues have been actively exploited by nation-state actors over the last few months.

CISA also urges to address the CVE-2018-14847 MikroTik Router OS Directory Traversal Vulnerability within June 1th 2022.

Another flaw added to the catalog is the CVE-2021-40438 Apache HTTP Server-Side Request Forgery (SSRF) vulnerability that must be addressed by December 15, 2021. A few days ago, the German Cybersecurity Agency and Cisco warned of attacks exploiting the recently patched CVE-2021-40438 flaw in Apache HTTP servers.

The German BSI agency published an alert about this vulnerability, it is aware of at least one attack exploiting this flaw.

The fifth issue added to the list of actively exploited vulnerabilities is the CVE-2020-11261 Improper Input Validation flaw that impacts multiple Qualcomm chipsets. This vulnerability must be addressed by June 1th 2022.

Google warned that the Qualcomm vulnerability was exploited by threat actors in limited, targeted attacks.

“There are indications that CVE-2020-11261 may be under limited, targeted exploitation” reads a note added to the January security bulletin last week.

The CVE-2020-11261 flaw was reported to Qualcomm by Google’s Android Security team on August 20, 2020 and was addressed in January 2021.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Zoho)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/125228/hacking/cisa-known-exploited-vulnerabilities.html