ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Ransomware gangs are exploiting IBM Aspera Faspex RCE flaw (CVE-2022-47986)

criticalRansomware exploited in the wildimportance 60CVE-2022-47986

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-47986
YAML Deserialization RCE in IBM Aspera Faspex

IBM Aspera Faspex, an enterprise high-speed file transfer platform, contains a deserialization flaw (CWE-502) that allows a remote attacker to execute code on the server by supplying crafted input that the application insecurely deserializes as YAML. An attacker who can reach the Faspex application can trigger the flaw and run arbitrary code in the context of the application, potentially leading to full compromise of the hosting server. Any organization running IBM Aspera Faspex is affected, with internet-exposed deployments at greatest risk since they provide direct reachability to the vulnerable application. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-02-21 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (top percentile). No public proof-of-concept is catalogued, but confirmed in-the-wild exploitation makes patching urgent.

Do: Apply IBM's update for Aspera Faspex per vendor instructions as the required action, prioritizing any Faspex instance reachable from the internet; restrict network access (firewall/VPN) until patched. Because ransomware actors have used this flaw, also review Faspex servers for signs of compromise, such as unexpected processes spawned by the application, anomalous requests to Faspex application endpoints, or new accounts and persistence mechanisms.

9.8100% KEV ransomware
  • IBM Aspera Faspex
moderate≈1,000–5,000 Faspex deployments, with on the order of a thousand or more internet-exposed (order-of-magnitude estimate)
Full article335 words · extracted from helpnetsecurity.com · click to collapse

Attackers are exploiting a critical vulnerability (CVE-2022-47986) in the IBM Aspera Faspex centralized file transfer solution to breach organizations.

exploiting CVE-2022-47986

About CVE-2022-47986

IBM Aspera Faspex is used by organizations to allow employees to quickly and securely exchange files with each other. (The files are uploaded to and downloaded from a centralized Aspera transfer server.)

CVE-2022-47986 is a YAML deserialization flaw that can be triggered by remote attackers sending a specially crafted obsolete API call. It affects IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier, and allows arbitrary code execution.

The problem, according to Rapid7’s security researcher Caitlin Condon, is that Aspera Faspex is typically installed on the network perimeter and – obviously – that some organizations haven’t plugged this particular security hole when IBM first made patches available.

Now, granted, its initial CVSS score (8.1) and the fact that it was the most highly scored vulnerability patched at the time might have had something to do with their decision not to patch quickly.

Unfortunately for them, the score was subsequently raised to 9.8 (out of 10) to reflect its real severity. But, more importantly, Max Garrett – the researcher who unearthed it – released technical details and PoC exploit code.

Exploiting CVE-2022-47986

The attackers started exploiting it almost immediately, and they haven’t stopped since.

In early March, SentinelOne researchers spotted attackers wielding the IceFire ransomware hitting Linux boxes of organizations in Turkey, Iran, Pakistan, and the United Arab Emirates. Greynoise recorded several exploitation attempts in the last month.

Rapid7’s Condon also says that they are aware of at least one recent incident where a customer was compromised via CVE-2022-47986.

The company has shared indicators of compromise that might come in handy to those who have been compromised but have yet to have ransomware unleashed on their systems (if deploying ransomware and not data exfiltration and extortion was the plan).

Enterprise admins are advised to upgrade their IBM Aspera Faspex server immediately and to look for – and act on – evidence of compromise.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/03/30/exploiting-cve-2022-47986/