ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

3 Zero-Day Exploits Hit SonicWall Enterprise Email Security Appliances

criticalExploit / PoC exploited in the wildimportance 60CVE-2021-20021CVE-2021-20022CVE-2021-20023

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-20021
+1 in the same advisory: …20022
Improper Privilege Management in SonicWall Email Security 10.0.9.x Grants Admin Access

CVE-2021-20021 is an improper privilege management flaw (CWE-269) in SonicWall Email Security version 10.0.9.x. An unauthenticated remote attacker can trigger it by sending a crafted HTTP request to the vulnerable host, which allows the attacker to create a new administrative account on the Email Security instance. That administrative access gives an attacker full control over the email security platform (CVSS 9.8 with high confidentiality, integrity, and availability impact), enabling persistence, manipulation of email filtering, and a foothold from which to target downstream mail infrastructure. Any organization running SonicWall Email Security 10.0.9.x is affected, whether on hardware appliances (3300, 4300, 5050, 7050, 8300, 9000, 5000, 7000), as a virtual appliance, or via the hosted service. The flaw is being actively exploited in the wild: it was added to CISA's KEV on 2021-11-03 with known ransomware use (headlines tie SonicWall email appliance attacks to the HelloKitty gang), and EPSS estimates an 83.4% probability of exploitation within 30 days (100th percentile).

Do: Upgrade SonicWall Email Security from 10.0.9.x to the latest patched release per SonicWall's instructions, as required by CISA KEV. Audit the deployment for unrecognized administrative accounts created by attackers, review management-interface HTTP logs for suspicious requests, and restrict exposure of the management interface to trusted networks. Because this bug was one of three SonicWall zero-days actively exploited with known ransomware use (HelloKitty), also hunt for signs of compromise and follow-on ransomware activity.

9.8
group max
83% KEV ransomware
  • SonicWall Email Security 10.0.9.x
  • SonicWall Email Security Appliance 3300 Email Security 10.0.9.x
  • SonicWall Email Security Appliance 4300 Email Security 10.0.9.x
  • +8 more
large≈ tens of thousands of deployments (order of 10k–100k systems)
CVE-2021-20023
Post-Auth Path Traversal Arbitrary File Read in SonicWall Email Security 10.0.9.x

CVE-2021-20023 is a path traversal flaw (CWE-22) in SonicWall Email Security version 10.0.9.x that allows an attacker who has already authenticated to the product to read arbitrary files on the remote host via a crafted request. Because it is network-exploitable, requires only high-privileged (admin-level) credentials, and needs no user interaction, it is typically triggered with an administrator account or credentials compromised by an attacker. Successful exploitation exposes sensitive file contents, potentially including configuration data or credentials that enable follow-on compromise, and CISA notes known ransomware use. It affects organizations running SonicWall Email Security on hardware appliances (3300, 4300, 8300, 5000, 7000, 5050, 7050, 9000), the virtual appliance, and the hosted service. The flaw is being actively exploited: it was added to the CISA KEV on 2021-11-03 and headlines describe it as one of three zero-days actively exploited in SonicWall Email Security products in the wild.

Do: Upgrade all Email Security deployments (hardware appliances, virtual appliance, hosted) off the vulnerable 10.0.9.x line to SonicWall's patched release per the vendor's instructions. Because exploitation requires authenticated admin access, restrict the management interface to trusted admin networks or VPN, review and rotate administrator credentials, and check for signs of compromise (unexpected admin logins, unusual file reads) given the known ransomware use. Prioritize patching internet-reachable appliances, as the flaw is listed in the CISA KEV and federal remediation is required.

4.951% KEV ransomware
  • SonicWall Email Security 10.0.9.x
  • SonicWall Email Security Appliance (models 3300, 4300, 8300, 5000, 7000, 5050, 7050, 9000) firmware 10.0.9.x
  • SonicWall Email Security Virtual Appliance 10.0.9.x
  • +1 more
largeroughly tens of thousands of appliance/virtual-appliance deployments plus hosted tenants (order-of-magnitude estimate)
Full article558 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananApr 21, 2021

SonicWall has addressed three critical security vulnerabilities in its hosted and on-premises email security (ES) product that are being actively exploited in the wild.

Tracked as CVE-2021-20021 and CVE-2021-20022, the flaws were discovered and reported to the company by FireEye's Mandiant subsidiary on March 26, 2021, after the cybersecurity firm detected post-exploitation web shell activity on an internet-accessible system within a customer's environment that had SonicWall's ES application running on a Windows Server 2012 installation. A third flaw (CVE-2021-20023) identified by FireEye was disclosed to SonicWall on April 6, 2021.

FireEye is tracking the malicious activity under the moniker UNC2682.

"These vulnerabilities were executed in conjunction to obtain administrative access and code execution on a SonicWall ES device," researchers Josh Fleischer, Chris DiGiamo, and Alex Pennino said.

The adversary leveraged these vulnerabilities, with intimate knowledge of the SonicWall application, to install a backdoor, access files, and emails, and move laterally into the victim organization's network."

A brief summary of the three flaws are below -

  • CVE-2021-20021 (CVSS score: 9.4) - Allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host
  • CVE-2021-20022 (CVSS score: 6.7) - Allows a post-authenticated attacker to upload an arbitrary file to the remote host, and
  • CVE-2021-20023 (CVSS score: 6.7) - A directory traversal flaw that allows a post-authenticated attacker to read an arbitrary file on the remote host.

The administrative access not only enabled the attacker to exploit CVE-2021-20023 to read configuration files, counting those containing information about existing accounts as well as Active Directory credentials but also abuse CVE-2021-20022 to upload a ZIP archive containing a JSP-based web shell called BEHINDER that's capable of accepting encrypted command-and-control (C2) communications.

"With the addition of a web shell to the server, the adversary had unrestricted access to the command prompt, with the inherited permissions of the NT AUTHORITY\SYSTEM account," FireEye said, adding the attacker then used "living off the land" (LotL) techniques to harvest credentials, move laterally across the network, and even "compress a subdirectory [that] contains daily archives of emails processed by SonicWall ES."

In the incident observed by the firm, the threat actor is said to have escalated their attack by conducting an internal reconnaissance activity, albeit briefly, prior to being isolated and removed from the environment, thus foiling their mission. The true motive behind the intrusion remains unclear.

SonicWall users are recommended to upgrade to 10.0.9.6173 Hotfix for Windows and 10.0.9.6177 Hotfix for hardware and ESXi virtual appliances. The SonicWall Hosted Email Security product was automatically patched on April 19 and hence no additional action is required.

UPDATE

The Milpitas-headquartered network security firm labeled the findings as an outcome of routine collaboration with third-party researchers and forensic analysis firms to ensure its products adhere to the security best practices.

"Through the course of this process, SonicWall was made aware of and verified certain zero-day vulnerabilities — in at least one known case, being exploited in the wild — to its hosted and on-premises email security products," the company said in a statement to The Hacker News. "SonicWall designed, tested and published patches to correct the issues and communicated these mitigations to customers and partners."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/04/3-zero-day-exploits-hit-sonicwall.html