ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Xfinity Discloses Data Breach Impacting Nearly 36 Million

criticalData breach exploited in the wildimportance 60CVE-2023-4966

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-4966
Info-Disclosure Buffer Overflow (CitrixBleed) in Citrix NetScaler ADC/Gateway

Citrix NetScaler ADC and NetScaler Gateway appliances contain a buffer overflow (CWE-119) that leaks sensitive information from device memory when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. A remote attacker who can reach such a configuration can trigger the overflow and read memory contents, harvesting sensitive data such as session tokens (a technique that enables session hijacking which can bypass multi-factor authentication). Any organization running an affected NetScaler ADC or Gateway appliance in these configurations is exposed, with appliances deployed as VPN or access gateways being the primary concern. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2023-10-18 with known ransomware use and a 100% EPSS exploitation probability, although no public proof-of-concept is known at this time. Because tokens stolen from memory can remain valid even after patching, responders must terminate all active and persistent sessions as part of remediation.

Do: Upgrade affected appliances to the patched builds cited in Citrix's advisory, then immediately kill all active and persistent ICA/AAA sessions per the vendor instructions, since patching alone does not invalidate session tokens attackers may have already stolen. If patching is not immediately possible, discontinue use of the affected Gateway/AAA configurations as CISA directs. Given known ransomware abuse, also hunt for signs of exploitation such as logins from unexpected sources, anomalous session reuse, or suspicious mailbox changes, and reset credentials for potentially exposed accounts.

7.5100% KEV ransomware
  • Citrix NetScaler ADC and NetScaler Gateway
masshundreds of thousands of internet-exposed NetScaler ADC/Gateway appliances (public internet scan counts), plus an unknown number of VPN-only or internal…
Full article311 words · extracted from infosecurity-magazine.com · click to collapse

Comcast Cable’s Xfinity brand has revealed a major data breach impacting 35.9 million customers, that resulted from exploitation of a Citrix vulnerability.

The telecoms company said that despite “promptly” patching the software flaw first announced by Citrix on October 10, it wasn’t quick enough to stop threat actors exploiting it.

“Citrix issued additional mitigation guidance on October 23, 2023. Xfinity promptly patched and mitigated the Citrix vulnerability within its systems,” the breach notice explained.

“However, during a routine cybersecurity exercise on October 25, Xfinity discovered suspicious activity and subsequently determined that between October 16 and October 19, 2023, there was unauthorized access to its internal systems that was concluded to be a result of this vulnerability.”

Reports suggested that the vulnerability (CVE-2023-4966) had been exploited in the wild as far back as August 2023. Found in Citrix NetScaler ADC and NetScaler Gateway appliances, exploitation allows threat actors to bypass multi-factor authentication (MFA) and hijack user sessions.

Read more on Citrix Bleed: LockBit Affiliates are Exploiting Citrix Bleed, Government Agencies Warn

Xfinity said that it determined on November 16 that its attackers had accessed customer data. This includes usernames and hashed passwords for all, and for “some customers,” potentially other information such as names, contact information, the last four digits of social security numbers, dates of birth and/or secret questions and answers.

The firm has issued a password reset across all affected accounts and recommended customers enable multi-factor authentication (MFA).

“While Xfinity advises customers not to re-use passwords across multiple accounts, the company is recommending that customers change passwords for other accounts for which they use the same username and password or security question,” it added.

Although the firm did not explicitly reveal the number of customers impacted, a notice published by the Office of the Maine Attorney General did have the figure.

Image credit: Ken Wolter / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/xfinity-discloses-data-breach-36/