ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

U.S. Cybersecurity Agency CISA Adds Three New Vulnerabilities in KEV Catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-31813
+1 in the same advisory: …26377
Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism.

Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

NVD description · AI analysis pending
9.8
group max
4%
  • apache http server
  • apache clustered data ontap
  • apache fedora
CVE-2022-41223
+1 in the same advisory: …40765
Authenticated Code Injection in Mitel MiVoice Connect Director (through 19.3)

CVE-2022-41223 is a code-injection flaw (CWE-94) in the Director database component of Mitel MiVoice Connect through version 19.3 (22.22.6100.0), caused by insufficient restrictions on database data types. An attacker who is already authenticated with high-privilege access to the affected component can submit specially crafted data that is injected and executed. Successful exploitation yields high-impact results — confidentiality, integrity, and availability of the system can all be compromised — and CISA notes it has seen known ransomware use. All organizations running Mitel MiVoice Connect with Director at or below the affected build are potentially exposed, with the practical attack surface limited to those who can reach the Director interface (the CVSS vector is adjacent-network with high privileges required). The vulnerability was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-02-21 with ransomware use confirmed, but no public proof-of-concept is known, so defenders should assume active exploitation.

Do: Apply the vendor-supplied update for MiVoice Connect per Mitel's instructions, ensuring Director is running a build later than 19.3 (22.22.6100.0). Until patched, restrict access to the Director web component to trusted admin networks, review and harden high-privilege account credentials, and monitor for signs of exploitation given confirmed ransomware use. Check with your Mitel reseller or the vendor advisory for the exact fixed version applicable to your deployment.

6.811% KEV ransomware
  • Mitel MiVoice Connect (Director database component) through 19.3 (22.22.6100.0)
large≈tens of thousands of on-premises deployments worldwide (exact counts not published)
CVE-2022-47986
YAML Deserialization RCE in IBM Aspera Faspex

IBM Aspera Faspex, an enterprise high-speed file transfer platform, contains a deserialization flaw (CWE-502) that allows a remote attacker to execute code on the server by supplying crafted input that the application insecurely deserializes as YAML. An attacker who can reach the Faspex application can trigger the flaw and run arbitrary code in the context of the application, potentially leading to full compromise of the hosting server. Any organization running IBM Aspera Faspex is affected, with internet-exposed deployments at greatest risk since they provide direct reachability to the vulnerable application. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-02-21 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (top percentile). No public proof-of-concept is catalogued, but confirmed in-the-wild exploitation makes patching urgent.

Do: Apply IBM's update for Aspera Faspex per vendor instructions as the required action, prioritizing any Faspex instance reachable from the internet; restrict network access (firewall/VPN) until patched. Because ransomware actors have used this flaw, also review Faspex servers for signs of compromise, such as unexpected processes spawned by the application, anomalous requests to Faspex application endpoints, or new accounts and persistence mechanisms.

9.8100% KEV ransomware
  • IBM Aspera Faspex
moderate≈1,000–5,000 Faspex deployments, with on the order of a thousand or more internet-exposed (order-of-magnitude estimate)
CVE-2023-0669
Pre-Authentication Deserialization RCE in Fortra GoAnywhere MFT

Fortra (formerly HelpSystems) GoAnywhere MFT is vulnerable to pre-authentication remote code execution (CWE-502) in the License Response Servlet, which deserializes an attacker-controlled object without validating it. An unauthenticated attacker who can reach the exposed administrative interface can send a crafted serialized object to the servlet and trigger code execution on the server. Successful exploitation gives the attacker the ability to run arbitrary code in the context of the application, which has been leveraged for ransomware operations. All organizations running GoAnywhere MFT with the affected component reachable by untrusted networks are in scope. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-10, ransomware use is confirmed, and EPSS puts the 30-day exploitation probability at 100%.

Do: Apply the vendor's updates for GoAnywhere MFT immediately, per Fortra's instructions, as required by the CISA KEV catalog. Until patched, restrict or block untrusted/internet access to the administrative interface hosting the License Response Servlet, and review logs for signs of exploitation given confirmed in-the-wild and ransomware use.

7.2100% KEV ransomware PoC ×3
  • Fortra GoAnywhere MFT
moderate≈1,000–10,000 internet-exposed GoAnywhere MFT instances (public internet scans of the exposed administrative interface)
Full article336 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananFeb 22, 2023Cyber Risk / Patch Management

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The list of shortcomings is as follows -

  • CVE-2022-47986 (CVSS score: 9.8) - IBM Aspera Faspex Code Execution Vulnerability
  • CVE-2022-41223 (CVSS score: 6.8) - Mitel MiVoice Connect Code Injection Vulnerability
  • CVE-2022-40765 (CVSS score: 6.8) - Mitel MiVoice Connect Command Injection Vulnerability

CVE-2022-47986 is described as a YAML deserialization flaw in the file transfer solution that could allow a remote attacker to execute code on the system.

Details of the flaw and a proof-of-concept (PoC) were shared by Assetnote on February 2, a day after which the Shadowserver Foundation said it "picked up exploitation attempts" in the wild.

The active exploitation of the Aspera Faspex flaw comes shortly after a vulnerability in Fortra's GoAnywhere MFT-managed file transfer software (CVE-2023-0669) was abused by threat actors with potential links to the Clop ransomware operation.

CISA also added two flaws impacting Mitel MiVoice Connect (CVE-2022-41223 and CVE-2022-40765) that could permit an authenticated attacker with internal network access to execute arbitrary code.

Exact specifics surrounding the nature of the attacks are unclear, but another flaw in MiVoice Connect was exploited last year to deploy ransomware. The vulnerabilities were patched by Mitel in October 2022.

In light of in-the-wild exploitation, Federal Civilian Executive Branch (FCEB) agencies are required to apply the necessary updates by March 14, 2023, to secure networks against potential threats.

CISA, in a related development, also released an Industrial Control Systems (ICS) advisory that touches upon critical flaws (CVE-2022-26377 and CVE-2022-31813) in Mitsubishi Electric's MELSOFT iQ AppPortal.

"Successful exploitation of these vulnerabilities could allow a malicious attacker to make unidentified impacts such as authentication bypass, information disclosure, denial-of-service, or bypass IP address authentication," the agency said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/02/us-cybersecurity-agency-cisa-adds-three.html