ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds IBM Aspera Faspex and Mitel MiVoice to Known Exploited Vulnerabilities Catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2022-47986CVE-2022-41223CVE-2022-40765

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-41223
+1 in the same advisory: …40765
Authenticated Code Injection in Mitel MiVoice Connect Director (through 19.3)

CVE-2022-41223 is a code-injection flaw (CWE-94) in the Director database component of Mitel MiVoice Connect through version 19.3 (22.22.6100.0), caused by insufficient restrictions on database data types. An attacker who is already authenticated with high-privilege access to the affected component can submit specially crafted data that is injected and executed. Successful exploitation yields high-impact results — confidentiality, integrity, and availability of the system can all be compromised — and CISA notes it has seen known ransomware use. All organizations running Mitel MiVoice Connect with Director at or below the affected build are potentially exposed, with the practical attack surface limited to those who can reach the Director interface (the CVSS vector is adjacent-network with high privileges required). The vulnerability was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-02-21 with ransomware use confirmed, but no public proof-of-concept is known, so defenders should assume active exploitation.

Do: Apply the vendor-supplied update for MiVoice Connect per Mitel's instructions, ensuring Director is running a build later than 19.3 (22.22.6100.0). Until patched, restrict access to the Director web component to trusted admin networks, review and harden high-privilege account credentials, and monitor for signs of exploitation given confirmed ransomware use. Check with your Mitel reseller or the vendor advisory for the exact fixed version applicable to your deployment.

6.811% KEV ransomware
  • Mitel MiVoice Connect (Director database component) through 19.3 (22.22.6100.0)
large≈tens of thousands of on-premises deployments worldwide (exact counts not published)
CVE-2022-47986
YAML Deserialization RCE in IBM Aspera Faspex

IBM Aspera Faspex, an enterprise high-speed file transfer platform, contains a deserialization flaw (CWE-502) that allows a remote attacker to execute code on the server by supplying crafted input that the application insecurely deserializes as YAML. An attacker who can reach the Faspex application can trigger the flaw and run arbitrary code in the context of the application, potentially leading to full compromise of the hosting server. Any organization running IBM Aspera Faspex is affected, with internet-exposed deployments at greatest risk since they provide direct reachability to the vulnerable application. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-02-21 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (top percentile). No public proof-of-concept is catalogued, but confirmed in-the-wild exploitation makes patching urgent.

Do: Apply IBM's update for Aspera Faspex per vendor instructions as the required action, prioritizing any Faspex instance reachable from the internet; restrict network access (firewall/VPN) until patched. Because ransomware actors have used this flaw, also review Faspex servers for signs of compromise, such as unexpected processes spawned by the application, anomalous requests to Faspex application endpoints, or new accounts and persistence mechanisms.

9.8100% KEV ransomware
  • IBM Aspera Faspex
moderate≈1,000–5,000 Faspex deployments, with on the order of a thousand or more internet-exposed (order-of-magnitude estimate)
Full article295 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 22, 2023

US CISA added actively exploited flaws in IBM Aspera Faspex and Mitel MiVoice to its Known Exploited Vulnerabilities Catalog.

US CISA added the following actively exploited flaws to its Known Exploited Vulnerabilities Catalog:

CVE-2022-47986 (CVSS score: 9.8) – IBM Aspera Faspex Code Execution Vulnerability – A remote attacker can trigger the vulnerability to execute arbitrary code on the system. The issue is caused by a YAML deserialization issue. Researchers from Shadowserver Fondation confirmed the active exploitation of the vulnerability in the wild.

Over the weekend we picked up exploitation attempts for IBM Aspera Faspex CVE-2022-47986 (unauthenticated RCE), a file exchange application. IBM issued a patch on Feb 2 addressing this & other vulnerabilities: https://t.co/TyWC9QmKHJ Exploit code is public, make sure to update!

— Shadowserver (@Shadowserver) February 13, 2023

Researchers from security firm Assetnote published a proof-of-concept (PoC) exploit code early the month.

CVE-2022-41223 (CVSS score: 6.8) – Mitel MiVoice Connect Code Injection Vulnerability – An authenticated attacker with internal network access can trigger the flaw to execute code within the context of the application.

CVE-2022-40765 (CVSS score: 6.8) – The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this flaw by March 14, 2023.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, KEV Catalog)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/142574/security/known-exploited-vulnerabilities-catalog-bugs.html