ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Attackers are exploiting zero-day in Pulse Secure VPNs to breach orgs (CVE-2021-22893)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-11510
Unauthenticated Arbitrary File Read in Ivanti Pulse Connect Secure VPN

Ivanti Pulse Connect Secure, an enterprise SSL VPN appliance, contains an arbitrary file read vulnerability (CWE-22, path traversal) that requires no authentication. An unauthenticated remote attacker with network access to the appliance over HTTPS can send a specially crafted URI containing traversal sequences to read arbitrary files from the device. The attacker gains access to sensitive appliance files, potentially including configuration or credential material useful for further compromise, and CISA records known ransomware use of this flaw. Any organization running Pulse Connect Secure, especially gateways exposed to the internet for remote access, is affected. Exploitation is established: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a 100% probability of exploitation in the next 30 days, and no public PoC is known.

Do: Apply updates per Ivanti's instructions, the required action in the CISA KEV entry, prioritizing internet-facing Pulse Connect Secure gateways, and consult the vendor advisory for the applicable fixed release since no version range is provided here. Where patching is not immediate, restrict HTTPS access to the appliance and hunt for signs of exploitation (unexpected file reads, anomalous VPN logins or sessions, and follow-on ransomware activity), as CISA reports known ransomware use.

10.0100% KEV ransomware PoC ×2
  • Ivanti Pulse Connect Secure
largeTens of thousands of internet-exposed gateways (order of 10,000-100,000 systems; each typically serves hundreds of VPN users, so potentially millions of users)
CVE-2020-8243
Authenticated Arbitrary Code Execution via Template Upload in Ivanti Pulse Connect Secure

CVE-2020-8243 is a code injection flaw (CWE-94) in the administrator web interface of Ivanti Pulse Connect Secure versions prior to 9.1R8.2. An authenticated attacker with administrative privileges can upload a custom template through the admin interface, which results in arbitrary code execution on the appliance. Successful exploitation gives the attacker full control over the VPN gateway, including access to network traffic, stored credentials, and a foothold for pivoting into the internal network. Any organization running an affected Pulse Connect Secure version is exposed, and administrators should note the flaw requires admin-level access, which lowers risk when the management interface is not reachable by untrusted users. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and carries a very high EPSS score of about 91%, indicating active or highly likely exploitation; Pulse Secure VPN appliances broadly were also the target of APT exploitation activity in 2021.

Do: Upgrade Pulse Connect Secure to 9.1R8.2 or later per the vendor's instructions, as required by the CISA KEV listing. Restrict the admin web interface to trusted management networks and review appliances for suspicious custom templates, modified configurations, or added administrator accounts, since Pulse Secure devices have been a documented target of APT intrusion tooling.

7.291% KEV
  • Ivanti Pulse Connect Secure < 9.1R8.2
  • Ivanti Pulse Policy Secure
largetens of thousands of internet-exposed Pulse Connect Secure appliances (~20,000–30,000+ in public scans), with far more deployed for internal/remote access
CVE-2020-8260
Authenticated RCE in Ivanti Pulse Connect Secure admin web interface (pre-9.1R9)

Ivanti Pulse Connect Secure versions before 9.1R9 contain a vulnerability (mapped to CWE-434) in the administrative web interface in which compressed uploads are handled with uncontrolled gzip extraction. An authenticated attacker with high-privilege (admin-level) access to that interface can send a crafted gzip-compressed file, triggering arbitrary code execution on the appliance with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.2, AV:N/PR:H). Successful exploitation yields arbitrary code execution on the VPN appliance itself, effectively enabling full compromise of the gateway that terminates the organization's VPN sessions. Any organization running Pulse Connect Secure on a release prior to 9.1R9 is affected, making the typical target an enterprise or government SSL VPN appliance accessible to anyone holding admin credentials. Exploitation is in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 96.5% EPSS exploitation probability (100th percentile), and a public proof of concept is available.

Do: Upgrade Pulse Connect Secure to 9.1R9 or later per the vendor's instructions; given the related patch-bypass flaw CVE-2021-22937 and the 'new urgent update' headlines, ensure the most recent available 9.1R release is applied rather than relying solely on the original 9.1R9 fix. Restrict the admin web interface to trusted management networks and review administrative accounts. Because the flaw is on CISA's KEV list and CISA has published malware analysis reports for Pulse Secure-targeted samples, hunt patched and unpatched devices for signs of compromise (e.g., web shells or implants).

7.296% KEV PoC
  • ivanti connect secure all releases prior to 9.1R9 (< 9.1R9)
mass≈10^5 devices: a six-figure installed base of Pulse Connect Secure appliances, with tens of thousands internet-exposed in public scans at the time of the 2021…
CVE-2021-22893
Use-After-Free RCE in Ivanti Pulse Connect Secure License Services

Ivanti Pulse Connect Secure, a widely deployed SSL VPN appliance, contains a use-after-free vulnerability in its license services. A remote, unauthenticated attacker can trigger the flaw via the license services and gain arbitrary code execution on the appliance, which is a high-value target because it terminates VPN sessions for enterprise networks. Any organization running an affected Pulse Connect Secure release is potentially affected; the source data does not specify exact version ranges, so administrators should compare their release against Ivanti's advisory. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and its 47.2% EPSS score (99th percentile) indicates a high likelihood of exploitation within 30 days.

Do: Apply the updates per Ivanti's instructions immediately, as CISA's required action specifies. Because exploited appliances have often retained persistent webshells/backdoors even after patching, also hunt for indicators of compromise (modified appliance files, unexpected processes or accounts) and follow Ivanti's remediation guidance rather than only installing the update. Until patched, restrict or closely monitor internet access to the appliance.

10.047% KEV ransomware
  • Ivanti Pulse Connect Secure
largetens of thousands of internet-exposed Pulse Connect Secure VPN appliances (order of magnitude ~10^4-10^5)
Full article749 words · extracted from helpnetsecurity.com · click to collapse

Attackers have been exploiting several old and one zero-day vulnerability (CVE-2021-22893) affecting Pulse Connect Secure (PCS) VPN devices to breach a variety of defense, government, and financial organizations around the world, Mandiant/FireEye has warned on Tuesday.

cve-2021-22893

Phil Richards, the Chief Security Officer at Ivanti – the company that acquired Pulse Secure in late 2020 – said that the zero-day vulnerability “impacted a very limited number of customers,” and that the software updates plugging the flaw will be released in early May.

In the meantime, they’ve offered some workarounds that can mitigate the risk of exploitation of that particular vulnerability, as well as a tool that can help defenders check if their systems have been affected.

The attackers’ modus operandi

According to Mandiant/FireEye, several threat actors have been exploiting the four PCS flaws and using 12 malware families to circumvent authentication and gain backdoor access to the targeted devices.

One of these (UNC2630) is believed to operate on behalf of the Chinese government and is possibly connected to APT5 (aka Manganese). Another (UNC2717) could not be definitely tied to a government or known APT group.

“We observed UNC2630 harvesting credentials from various Pulse Secure VPN login flows, which ultimately allowed the actor to use legitimate account credentials to move laterally into the affected environments. In order to maintain persistence to the compromised networks, the actor utilized legitimate, but modified, Pulse Secure binaries and scripts on the VPN appliance,” FireEye researchers shared.

That allowed them to:

  • Trojanize shared objects with malicious code to log credentials and bypass authentication flows
  • Inject webshells into Internet-accessible Pulse Secure VPN appliance administrative web pages for the devices
  • Toggle the filesystem between Read-Only and Read-Write modes so they can make modifications
  • Maintain persistence on the appliances despite upgrades
  • Unpatch modified files and delete utilities and scripts after use to evade detection
  • Clear log files

The attackers have been at it since August 2020 and up until March 2021.

The exploited vulnerabilities

The attackers have been leveraging three previously known, exploited and already patched vulnerabilities in Pulse Connect Secure VPN devices: CVE-2019-11510, CVE-2020-8243 and CVE-2020-8260.

CVE-2019-11510 is a critical arbitrary file disclosure vulnerability that can be exploited by unauthenticated attackers. CVE-2020-8243 is a code injection flaw, CVE-2020-8260 is an unrestricted file upload vulnerability, and both require authentication prior to exploitation.

Not much has been shared about the zero-day (CVE-2021-22893), aside from it being an authentication bypass vulnerability that, given the highest awarded CVSSv3 score, is likely exploitable by a remote, unauthenticated attacker, requires no user interaction, and allows arbitrary code execution.

“Because it is a zero-day and the timetable for the release of a patch is not yet known, CVE-2021-22893 gives attackers a valuable tool to gain entry into a key resource used by many organizations, especially in the wake of the shift to the remote workforce over the last year,” noted Scott Caveza, Research Engineering Manager, Tenable.

“Attackers can utilize this flaw to further compromise the PCS device, implant backdoors and compromise credentials. While Pulse Secure has noted that the zero-day has seen limited use in targeted attacks, it’s just a matter of time before a proof-of-concept becomes publicly available, which we anticipate will lead to widespread exploitation, as we observed with CVE-2019-11510.”

Mitigation, remediation, and incident response

The vulnerability affects Pulse Connect Secure 9.0R3 and higher. The company has said that fixes for CVE-2021-22893 will be released in early May and that, until that moment, enterprise admins can implement a workaround: an .xml file that disables the appliance’s Windows File Share Browser and Pulse Secure Collaboration features.

In addition to this, they have released the Pulse Connect Secure Integrity Tool, which helps administrator check the integrity of the appliances’ file system and find additional or modified files. They also offered additional advice for impacted organizations.

“Organizations should examine available forensic evidence to determine if an attacker compromised user credentials. Ivanti highly recommends resetting all passwords in the environment and reviewing the configuration to ensure no service accounts can be used to authenticate to the vulnerability,” Mandiant/FireEye researchers noted.

The U.S. CISA has released an emergency directive ordering federal agencies to enumerate all instances of Pulse Connect Secure virtual and hardware appliances hosted by the agency or a third party on the agency’s behalf, and to deploy and run the latest version of the Pulse Connect Secure Integrity Tool on each of those instances. They offer specific guidance depending on the tool’s findings, as well as additional technical details and mitigation advice.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/04/21/cve-2021-22893/