New Log4j attacks target SolarWinds, ZyXEL devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-35247 | Actively Exploited Input Validation Flaw in SolarWinds Serv-U LDAP Login CVE-2021-35247 is an improper input validation flaw (CWE-20) in the SolarWinds Serv-U web login screen's LDAP authentication path, where submitted characters are not sufficiently sanitized before being passed to the LDAP server. It is triggered remotely over the network with no privileges or user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), by sending crafted, non-sanitized characters through the login-to-LDAP flow; SolarWinds notes that LDAP servers ignored the improper characters and no downstream effect was detected, and the 5.3 (medium) CVSS score reflects a low integrity impact with no confidentiality or availability impact. An attacker gains the ability to feed unsanitized input into the LDAP authentication process; no confirmed code execution or full compromise is documented for this specific bug, but it is nevertheless on CISA's Known Exploited Vulnerabilities catalog. Affected organizations are those running SolarWinds Serv-U whose web login screen uses LDAP authentication. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2022-01-21, Microsoft warned that threat actors attempted to exploit the Serv-U bug in real-world attacks, and reporting on this flaw surfaced alongside the Log4j (Log4Shell) attack wave targeting SolarWinds products. Do: Schedule an upgrade to the latest SolarWinds Serv-U release, which adds the required input validation and sanitization to the LDAP login path; this is the CISA KEV required action, so KEV deadlines apply. Until patched, restrict access to the Serv-U web login from untrusted networks and review LDAP/authentication logs for suspicious or malformed login input. While updating, also confirm Serv-U is patched for the related critical Serv-U 15.5 root code execution flaws and any Log4j exposure covered in the same reporting cycle. | 5.3 | 3% | KEV |
| moderate≈ several thousand internet-exposed Serv-U servers (estimate; no scan counts in source data) |
Full article357 words · extracted from therecord.media · click to collapse
Cybercriminals looking to capitalize on the Log4Shell vulnerability are attacking devices from SolarWinds and ZyXEL that are known to have used the Log4j library inside their software, according to two reports published on Wednesday by Microsoft and Akamai. The most urgent of these attacks are those spotted by Microsoft, which said it discovered a threat actor abusing Log4Shell in combination with a zero-day vulnerability in the SolarWinds Serv-U file-sharing server. Tracked as CVE-2021-35247, Microsoft said it reported the issue to SolarWinds, which has released a fix on Tuesday. Described as an input validation issue in the Serv-U web login screen, Microsoft said the attackers were using the zero-day to bypass input validation on the login process using non-standard characters and then using the Log4Shell exploit to take over Serv-U servers. In addition to these attacks, Akamai security researcher Larry Cashdollar also reported spotting a Mirai DDoS botnet going after ZyXEL networking devices. "It could be that Zyxel was specifically targeted since they published a blog stating they were impacted by the log4j vulnerability," Cashdollar said in a blog post on Wednesday. While news cycles move fast from topic to topic, the situation around the Log4Shell exploit has not changed since last month, and the vulnerability is still heavily targeted and abused by threat actors seeking to enter corporate networks. At the time of writing, there have been reports about threat actors such as ransomware gangs, nation-state cyber-espionage groups, crypto-mining gangs, initial access brokers, and DDoS botnets, all of which have used the vulnerability in past operations. Although the Apache Software Foundation has released patches for the Log4j library, attacks against applications that use the library are likely to continue because not all of these apps have released their own set of security updates, leaving many networks exposed to attacks and creating a fertile ground for exploitation that is bound to last for years.
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/new-log4j-attacks-target-solarwinds-zyxel-devices