CISA Warning: Nation-State Hackers Exploit Fortinet and Zoho Vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-44228 | JNDI Injection Remote Code Execution in Apache Log4j2 (Log4Shell) Apache Log4j2, an extremely widely used Java logging library, fails to protect its JNDI lookup feature against attacker-controlled JNDI-related endpoints (CWE-20, CWE-502), so crafted text processed by the logger causes the Java runtime to fetch and load attacker-supplied objects, leading to remote code execution. The flaw is triggered whenever attacker-controlled input reaches the logging API and is parsed for JNDI lookups, a pattern common in web servers and enterprise Java applications that log user-supplied fields such as headers or form values. Successful exploitation yields arbitrary code execution under the privileges of the affected application, giving attackers a foothold for lateral movement, data theft, and ransomware deployment. Any Java application or product that ships or bundles an affected Apache Log4j2 release is exposed, making this one of the most broadly deployed vulnerabilities ever disclosed. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-12-10 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days. Do: Inventory all Java applications and dependencies for Apache Log4j2 and apply the vendor's patched updates, or remove affected assets from the network, as required by CISA's KEV catalog. Where updates are not yet available, use the temporary mitigations in CISA's ED-22-02 recommended-mitigation guidance, such as disabling message lookups, only until patches are applied. Prioritize internet-facing and business-critical systems and hunt for exploitation activity given known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×9 |
| masshundreds of millions of Java applications/devices, with hundreds of thousands of internet-exposed services | |
| CVE-2022-42475 | Unauthenticated Heap Overflow in Fortinet FortiOS/FortiProxy SSL-VPN (Critical RCE) CVE-2022-42475 is a critical (CVSS 9.8) heap-based buffer overflow in the SSL-VPN service of Fortinet FortiOS and FortiProxy. A remote, unauthenticated attacker can trigger it by sending specifically crafted requests to an exposed SSL-VPN interface, with no user interaction or credentials required. Successful exploitation yields arbitrary code or command execution on the appliance, giving attackers a foothold on the perimeter device from which they can pivot into internal networks. Any organization running the listed FortiOS (6.0 through 7.2) or FortiProxy (7.0/7.2) versions with SSL-VPN enabled is affected. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, has near-certain exploitation probability (EPSS 99.5%), and has been used in targeted government attacks and a Chinese-nexus espionage campaign that compromised over 20,000 systems, with attackers also noted to retain access even after patching. Do: Upgrade FortiOS and FortiProxy to fixed releases per Fortinet advisory FG-IR-22-398 (any version beyond the listed affected ranges), and reboot the appliance after patching to clear lingering SSL-VPN sessions since attackers have been observed retaining access post-patch. Check for indicators of compromise such as unknown local accounts, unexpected processes, and anomalous historical logins, and rotate SSL-VPN credentials if compromise is suspected. If SSL-VPN is not required, disable it or restrict exposure to trusted sources until patched. | 9.8 | 99% | KEV ransomware PoC |
| masshundreds of thousands of internet-exposed FortiGate/FortiProxy SSL-VPN endpoints (well over 100,000; 20,000+ confirmed victims in a single campaign) | |
| CVE-2022-47966 | Unauthenticated SAML RCE in Zoho ManageEngine On-Premise Products CVE-2022-47966 is a critical (CVSS 9.8), unauthenticated remote code execution flaw in roughly two dozen Zoho ManageEngine on-premise products caused by their bundled Apache Santuario xmlsec (XML Security for Java) 1.4.1 library, in which the XSLT features leave security protections to the application and ManageEngine did not provide them. An attacker triggers the flaw by sending a crafted SAML response containing a malicious XSLT transform to the SAML single sign-on (SSO) endpoint; exploitation is only possible if SAML SSO has ever been configured for the product (for some products, SAML SSO must be currently active). Successful exploitation yields arbitrary code execution in the context of the affected ManageEngine application, typically full compromise of the server and a foothold into the wider enterprise network. Any organization running an affected product version with SAML SSO enabled is affected, with internet-exposed ITSM/identity-management servers the most likely targets. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, Rapid7 reported broad attacker interest, North Korea's Lazarus Group used it to deploy QuiteRAT, and Iranian government-backed actors have targeted U.S. energy and transit-sector organizations. Do: Apply vendor updates immediately, upgrading each installed product to at least the fixed version listed (e.g., ServiceDesk Plus 14004+, ADSelfService Plus 6211+, Endpoint Central/Endpoint Central MSP 10.1.2228.11+, Password Manager Pro 12124+, ServiceDesk Plus MSP 13001+, ADAudit Plus 7081+, ADManager Plus 7162+, AD360 4310+); this is a CISA KEV required action. As an interim mitigation, disable or restrict SAML SSO (or limit access to the product's SSO endpoints), since SAML SSO must have been configured for exploitation. Prioritize patching internet-exposed instances and review those servers for signs of compromise, given documented use by Lazarus Group, ransomware operators, and Iranian nation-state actors. | 9.8 | 100% | KEV ransomware PoC ×6 |
| largetens of thousands of installations plausibly affected (thousands of instances internet-exposed), out of ManageEngine's very large on-prem install base |
Full article531 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 08, 2023Endpoint Security / Exploit
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday warned that multiple nation-state actors are exploiting security flaws in Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus to gain unauthorized access and establish persistence on compromised systems.
“Nation-state advanced persistent threat (APT) actors exploited CVE-2022-47966 to gain unauthorized access to a public-facing application (Zoho ManageEngine ServiceDesk Plus), establish persistence, and move laterally through the network,” according to a joint alert published by the agency, alongside Federal Bureau of Investigation (FBI), and Cyber National Mission Force (CNMF).
The identities of the threat groups behind the attacks have not been disclosed, although the U.S. Cyber Command (USCYBERCOM) hinted at the involvement of Iranian nation-state crews.
The findings are based on an incident response engagement conducted by CISA at an unnamed aeronautical sector organization from February to April 2023. There is evidence to suggest that the malicious activity commenced as early as January 18, 2023.
CVE-2022-47966 refers to a critical remote code execution flaw that allows an unauthenticated attacker to completely take over susceptible instances.
Following the successful exploitation of CVE-2022-47966, the threat actors obtained root-level access to the web server and took steps to download additional malware, enumerate the network, collect administrative user credentials, and move laterally through the network.
It’s not immediately clear if any proprietary information was stolen as a result.
The entity in question is also said to have been breached using a second initial access vector that entailed the exploitation of CVE-2022-42475, a severe bug in Fortinet FortiOS SSL-VPN, to access the firewall.
“It was identified that APT actors compromised and used disabled, legitimate administrative account credentials from a previously hired contractor—of which the organization confirmed the user had been disabled prior to the observed activity,” CISA said.
The attackers have also been observed initiating multiple Transport Layer Security (TLS)-encrypted sessions to several IP addresses, indicating data transfer from the firewall device, in addition to leveraging valid credentials to hop from the firewall to a web server and deploy web shells for backdoor access.
In both instances, the adversaries are said to have disabled administrative account credentials and deleted logs from several critical servers in the environment in an attempt to erase the forensic trail of their activities.
“Between early-February and mid-March 2023, anydesk.exe was observed on three hosts,” CISA noted. “APT actors compromised one host and moved laterally to install the executable on the remaining two.”
It’s currently not known how AnyDesk was installed on each machine. Another technique used in the attacks entailed the use of the legitimate ConnectWise ScreenConnect client to download and run the credential dumping tool Mimikatz.
What’s more, the actors attempted to exploit a known Apache Log4j vulnerability (CVE-2021-44228 or Log4Shell) in the ServiceDesk system for initial access but were ultimately unsuccessful.
In light of continued exploitation of the security flaws, it’s recommended that organizations apply the latest updates, monitor for unauthorized use of remote access software, and purge unnecessary accounts and groups to prevent their abuse.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/09/cisa-warning-nation-state-hackers.html