ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Alert: Juniper Firewalls, Openfire, and Apache RocketMQ Under Attack from New Exploits

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-32315
Unauthenticated Path Traversal in Ignite Realtime Openfire Admin Console

CVE-2023-32315 is an unauthenticated path traversal flaw (CWE-22) in the Ignite Realtime Openfire XMPP server that allows a remote attacker to reach pages of the Openfire Admin Console that are reserved for administrative users. It is triggered by sending a crafted HTTP request to the admin console web interface containing path traversal sequences, which bypasses the authentication check protecting those restricted pages. Successful exploitation exposes administrative console functionality to an unauthenticated attacker, potentially enabling further compromise of the server and the chat environment it hosts. Any organization running Openfire is affected, particularly instances whose admin console interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-08-24 and carries an EPSS probability of 100% (top percentile), indicating active exploitation in the wild; ransomware use is not yet documented.

Do: Upgrade Openfire to the patched release recommended in the Ignite Realtime advisory for CVE-2023-32315, per the CISA KEV required action; if patching must be delayed, restrict the admin console (default ports 9090/9091) to trusted networks or place it behind a VPN. Review access logs for requests to admin console pages containing traversal sequences, and check for unauthorized admin accounts or configuration changes, since KEV listing confirms exploitation in the wild.

7.5100% KEV PoC ×2
  • Ignite Realtime Openfire
large≈ tens of thousands of internet-exposed Openfire servers (~30,000–40,000 per public scans)
CVE-2023-33246
Unauthenticated Remote Command Execution in Apache RocketMQ

CVE-2023-33246 is an unauthenticated remote command execution flaw in Apache RocketMQ: when NameServer, Broker, or Controller components are exposed without access controls, an attacker can invoke the update-configuration function or forge RocketMQ protocol messages to inject and run operating-system commands. Commands execute with the privileges of the system user running RocketMQ, giving an attacker full control of the message broker host. Any organization running RocketMQ 5.1.0 or below (5.x) or versions below 4.9.6 (4.x) with these components reachable by untrusted networks is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-06, carries a 96.6% EPSS probability of exploitation, has multiple public PoC exploits, and is being leveraged by the Muhstik botnet to expand DDoS operations alongside other malware campaigns.

Do: Upgrade to RocketMQ 5.1.1 or above for 5.x deployments, or 4.9.6 or above for 4.x, per the KEV required action. Until patched, restrict NameServer, Broker, and Controller ports to trusted clients only and avoid exposing them to the internet without authentication or access filtering. Check patched hosts for signs of compromise (unauthorized processes, cron jobs, or botnet activity such as Muhstik), since active exploitation is documented.

9.897% KEV PoC ×4
  • Apache RocketMQ 5.x through 5.1.0 (upgrade to 5.1.1 or above)
  • Apache RocketMQ 4.x below 4.9.6 (upgrade to 4.9.6 or above)
largeTens of thousands of internet-exposed instances plausible (thousands confirmed in public scans; total installed base larger, exact count unknown)
CVE-2023-36845
+3 in the same advisory: …36846 …36844 …36847
Unauthenticated RCE in Juniper J-Web on EX and SRX Series

A PHP external variable modification flaw (CVE-2023-36845) in the J-Web web management interface of Juniper Networks Junos OS on EX Series switches and SRX Series firewalls allows an unauthenticated, network-based attacker to remotely execute code. By sending a crafted request that sets the PHPRC variable, the attacker modifies the PHP execution environment to inject and execute code, gaining full control of the device with high impact on confidentiality, integrity, and availability (CVSS 9.8). All EX and SRX devices running affected Junos OS versions — from all builds prior to 20.4R3-S9 through the 23.2 line — are affected where the J-Web interface is reachable. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on November 13, 2023, public PoC exploit code is available, and public scans found nearly 12,000 vulnerable Juniper firewalls exposed to the internet, prompting a CISA patch deadline of November 17.

Do: Upgrade affected EX/SRX devices to a fixed Junos OS release: 20.4R3-S9, 21.2R3-S7, 21.3R3-S5, 21.4R3-S5, 22.1R3-S4, 22.2R3-S2, 22.3R2-S2 or 22.3R3-S1, 22.4R2-S1 or 22.4R3, or 23.2R1-S1 or 23.2R2 (or later). As an interim mitigation, disable J-Web or restrict access to trusted management networks, and review web interface logs for crafted requests setting PHPRC. Federal defenders should patch by CISA's November 17 KEV deadline.

9.8
group max
95% KEV PoC ×2
  • Juniper Networks Junos OS (J-Web on EX Series and SRX Series) All versions prior to 20.4R3-S9; all 21.1 versions (21.1R1 and later); 21.2 prior to 21.2R3-S7; 21.3 prior to 21.3R3-S5; 21.4 prior to 21.4R3-S5; 22.1 prior to
large≈12,000 internet-exposed Juniper firewalls (public vulnerability scans); total installed base likely higher
Full article842 words · extracted from thehackernews.com · click to collapse

Recently disclosed security flaws impacting Juniper firewalls, Openfire, and Apache RocketMQ servers have come under active exploitation in the wild, according to multiple reports.

The Shadowserver Foundation said that it's "seeing exploitation attempts from multiple IPs for Juniper J-Web CVE-2023-36844 (& friends) targeting /webauth_operation.php endpoint," the same day a proof-of-concept (PoC) became available.

The issues, tracked as CVE-2023-36844, CVE-2023-36845, CVE-2023-36846, and CVE-2023-36847, reside in the J-Web component of Junos OS on Juniper SRX and EX Series. They could be chained by an unauthenticated, network-based attacker to execute arbitrary code on susceptible installations.

Patches for the flaw were released on August 17, 2023, a week after which watchTowr Labs published a proof-of-concept (PoC) by combining CVE-2023-36846 and CVE-2023-36845 to execute a PHP file containing malicious shellcode.

Currently, there are more than 8,200 Juniper devices that have their J-Web interfaces exposed to the internet, most of them from South Korea, the U.S., Hong Kong, Indonesia, Turkey, and India.

Kinsing Exploits Openfire Vulnerability

Another vulnerability that has been weaponized by threat actors is CVE-2023-32315, a high-severity path traversal bug in Openfire's administrative console that could be leveraged for remote code execution.

"This flaw allows an unauthorized user to exploit the unauthenticated Openfire Setup Environment within an established Openfire configuration," cloud security firm Aqua said.

"As a result, a threat actor gains access to the admin setup files that are typically restricted within the Openfire Admin Console. Next, the threat actor can choose between either adding an admin user to the console or uploading a plugin which will eventually allow full control over the server."

Threat actors associated with the Kinsing malware botnet have been observed utilizing the flaw to create a new admin user and upload a JAR file, which contains a file named cmd.jsp that acts as a web shell to drop and execute the malware and a cryptocurrency miner.

Aqua said it found 6,419 internet-connected servers with Openfire service running, with a majority of the instances located in China, the U.S., and Brazil.

Apache RocketMQ Vulnerability Targeted by DreamBus Botnet

In a sign that threat actors are always on the lookout for new flaws to exploit, an updated version of the DreamBus botnet malware has been observed taking advantage of a critical-severity remote code execution vulnerability in RocketMQ servers to compromise devices.

CVE-2023-33246, as the issue is cataloged as, is a remote code execution flaw impacting RocketMQ versions 5.1.0 and below that enables an unauthenticated attacker to run commands with the same access level as that of the system user process.

In the attacks detected by Juniper Threat Labs since June 19, 2023, successful exploitation of the flaw paves the way for the deployment of a bash script called "reketed," which acts as the downloader for the DreamBus botnet from a TOR hidden service.

DreamBus is a Linux-based malware that's a variant of SystemdMiner and is engineered to mine cryptocurrency on infected systems. Active since early 2019, it's been known to be propagated by specifically exploiting remote code execution vulnerabilities.

"As part of the installation routine, the malware terminates processes, and eliminates files associated with outdated versions of itself," security researcher Paul Kimayong said, adding it sets up persistence on the host by means of a cron job.

"However, the presence of a modular bot like the DreamBus malware equipped with the ability to execute bash scripts provides these cybercriminals the potential to diversify their attack repertoire, including the installation of various other forms of malware."

Exploitation of Cisco ASA SSL VPNs to Deploy Akira Ransomware

The developments come amid cybersecurity firm Rapid7 warning of an uptick in threat activity dating back to March 2023 and targeting Cisco ASA SSL VPN appliances in order to deploy Akira and LockBit ransomware.

While some instances have entailed the use of credential stuffing, activity in others "appears to be the result of targeted brute-force attacks on ASA appliances where multi-factor authentication (MFA) was either not enabled or was not enforced for all users," the company said.

Cisco has acknowledged the attacks, noting that the threat actors could also be purchasing stolen credentials from the dark web to infiltrate organizations.

This hypothesis is further bolstered by the fact that an initial access broker referred to as Bassterlord was observed selling a guide on breaking into corporate networks in underground forums earlier this February.

"Notably, the author claimed they had compromised 4,865 Cisco SSL VPN services and 9,870 Fortinet VPN services with the username/password combination test:test," Rapid7 said.

"It's possible that, given the timing of the dark web discussion and the increased threat activity we observed, the manual's instruction contributed to the uptick in brute force attacks targeting Cisco ASA VPNs."

The disclosures also arrive as unpatched Citrix NetScaler ADC and Gateway appliances are at heightened risk of opportunistic attacks by ransomware actors who are making use of a critical flaw in the products to drop web shells and other payloads.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/08/alert-juniper-firewalls-openfire-and.html