ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Chinese Velvet Ant Uses Cisco Zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-20399

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-20399
Authenticated Command Injection in Cisco NX-OS Grants Root Privileges

CVE-2024-20399 is a command injection flaw (CWE-78) in the CLI of Cisco NX-OS Software, caused by insufficient validation of arguments passed to specific configuration CLI commands. An authenticated attacker who already holds Administrator credentials can trigger it by submitting crafted input as the argument of an affected configuration command, gaining the ability to execute arbitrary commands as root on the device's underlying operating system. Because Administrator access is required, the flaw is effectively a privilege-escalation issue following credential compromise, and it grants no additional privilege on Nexus 3000 Series, Nexus 7000 Series running NX-OS 8.1(1) or later, and Nexus 9000 Series in standalone NX-OS mode, which already allow administrative bash-shell access to the OS. Any organization running affected NX-OS on Cisco Nexus switching is in scope, with the practical risk concentrated in environments where admin credentials may have been stolen. Exploitation has been observed in the wild: the China-linked group 'Velvet Ant' (associated with Salt Typhoon) used it as a zero-day to compromise U.S. ISPs and telecom providers, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-02.

Do: Upgrade affected Nexus switches to a fixed NX-OS release per Cisco's security advisory, as required by the CISA KEV listing (apply mitigations per vendor instructions or discontinue use if fixes are unavailable). Restrict and audit Administrator-level CLI access on NX-OS devices, and hunt for suspicious configuration-command activity or unexplained root-level actions, given Velvet Ant/Salt Typhoon targeting of telecom and ISP networks. For Nexus 3000, Nexus 7000 (8.1(1)+), and Nexus 9000 standalone-mode devices the flaw adds no privilege, but patching is still recommended.

6.74% KEV
  • Cisco NX-OS Software (Cisco Nexus switches)
masshundreds of thousands of NX-OS/Nexus devices deployed across enterprise and data-center networks (no authoritative public install count)
Full article415 words · extracted from infosecurity-magazine.com · click to collapse

A Chinese cyber espionage group has been observed deploying custom malware after jailbreaking a Cisco switch appliance using a recently discovered zero-day exploit.

While investigating the attack techniques of Velvet Ant, an advanced persistent threat (APT) group believed to be sponsored by China, cybersecurity firm Sygnia discovered in July 2024 that the group had exploited a zero-day command injection vulnerability in Cisco’s NX-OS (CVE-2024-20399).

NX-OS is a network operating system designed specifically for Cisco’s Nexus-series switches.

In a new August 22 report, Sygnia reveals that the threat actor used the zero-day exploit to deploy custom malware.

Leveraging a Zero-Day to Deploy Malware

The zero-day exploit allows an attacker with valid administrator credentials to the switch management console to escape the NX-OS command line interface (CLI) and execute arbitrary commands on the Linux underlying operating system.

Exploiting this vulnerability allowed Velvet Ant to compromise and control on-premises Cisco switch appliances and use them as a main pivot to access additional network devices, allowing for clear identification of additional activities originating from known compromised locations.

Following the exploitation, Velvet Ant deployed tailored malware, which runs on the underlying operating system and is invisible to common security tools.

The malware, that Sygnia called VelvetShell, is a hybrid customized version of two open-source tools: TinyShell, a Unix backdoor and a proxy tool named 3proxy.

With this escalating evasion tactic, the APT group can maintain long-term network persistence, which is critical when deploying a cyber espionage campaign.

Cisco released a fix for this vulnerability on July 1, 2024.

A few days later, the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog.

Velvet Ant’s Multi-Year Intrusion Campaigns

This zero-day exploit was part of a multi-year intrusion campaign detected by Sygnia in 2023.

The campaign included the exploitation of several footholds in the target organizations’ networks.

This sophisticated approach indicates a comprehensive understanding of the target’s environment, Sygnia noted in campaign analysis.

“Over the years of espionage activities, Velvet Ant increased their sophistication, using evolving tactics to continue their cyber operations in a victim network – from operating on ordinary endpoints, shifting operations to legacy servers and finally moving towards network appliances and using 0-days” The firm commented.  

“The determination, adaptability and persistence of such threat actors highlights the sensitivity of a holistic response plan not only to contain and mitigate the threat but also monitor the network for additional attempts to exploit the network,” the Sygnia researchers concluded.

Photo credit: pchow98/Flickr

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/chinese-velvet-ant-cisco-0day/