Edge device vulnerabilities fueled attack sprees in 2024
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-21887 +1 in the same advisory: …46805 | Command Injection RCE in Ivanti Connect Secure and Policy Secure Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available. Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories. | 9.1 group max | 100% | KEV ransomware PoC |
| largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher) | |
| CVE-2024-0012 +1 in the same advisory: …9474 | Authentication Bypass in Palo Alto Networks PAN-OS Management Interface CVE-2024-0012 is a critical authentication bypass (CWE-306) in the web management interface of Palo Alto Networks PAN-OS that lets an unauthenticated attacker with network access to that interface gain full PAN-OS administrator privileges. It is triggered simply by sending requests to an exposed management web interface, with no credentials or user interaction required. Once inside, the attacker can perform administrative actions, tamper with device configuration, and chain the bug with the related privilege escalation flaw CVE-2024-9474 for deeper compromise. Only PAN-OS 10.2, 11.0, 11.1 and 11.2 are affected; Cloud NGFW and Prisma Access are not, and risk is greatly reduced when the management interface is restricted to trusted internal IP addresses per vendor best practice. The flaw is being actively exploited: it was added to CISA KEV on 2024-11-18 with known ransomware use, and public reporting describes an ongoing campaign that has compromised more than 2,000 Palo Alto devices using this bug chained with CVE-2024-9474. Do: Upgrade PAN-OS 10.2, 11.0, 11.1 and 11.2 deployments to the patched releases listed in the vendor advisory (security.paloaltonetworks.com/CVE-2024-0012), ensuring the chained privilege escalation bug CVE-2024-9474 is also addressed. Until patched, never expose the management web interface to untrusted networks or the internet, and restrict access to trusted internal IP addresses only. Review device logs and configurations for signs of compromise (unexpected admin activity or configuration changes) and hunt for persistence on any internet-exposed device. | 9.3 group max | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed PAN-OS management interfaces, with 2,000+ devices already confirmed compromised | |
| CVE-2024-3400 | Unauthenticated Root Command Injection in Palo Alto Networks PAN-OS GlobalProtect Palo Alto Networks PAN-OS contains a command injection flaw (CWE-77, with improper input validation per CWE-20) in its GlobalProtect feature, allowing an unauthenticated attacker to execute arbitrary operating-system commands with root privileges on the affected firewall. The flaw is triggered through the GlobalProtect interface, which in most deployments is reachable from untrusted networks, so no valid user credentials or prior access are required. Successful exploitation yields full root control of the firewall, the most powerful position in a network perimeter, enabling traffic interception, configuration tampering, and use as a foothold for further compromise. All PAN-OS firewalls running affected releases with the GlobalProtect feature are exposed; CISA added the issue to the KEV catalog on 2024-04-12 with ransomware use noted, and EPSS puts the 30-day exploitation probability at 100% (100th percentile). No public proof-of-concept is recorded in the source data, but confirmed in-the-wild exploitation makes patching urgent. Do: Apply the PAN-OS patches released in Palo Alto Networks' bulletin according to its published patch schedule, prioritizing internet-facing firewalls. Until patched, enable the vendor's Threat Prevention signatures as required by CISA KEV, restrict exposure of the GlobalProtect interface to trusted sources where possible, and review logs and device configuration for signs of compromise given confirmed exploitation with known ransomware use. | 10.0 | 100% | KEV ransomware PoC ×2 |
| large≈10,000–100,000 internet-exposed PAN-OS firewalls with GlobalProtect enabled | |
| CVE-2024-47575 | Unauthenticated RCE in Fortinet FortiManager and FortiManager Cloud CVE-2024-47575 is a missing-authentication flaw (CWE-306) in Fortinet FortiManager and FortiManager Cloud, rated critical at CVSS 9.8. An unauthenticated remote attacker can send specially crafted requests to the affected management interface and execute arbitrary code or commands, with no credentials, privileges, or user interaction required. Every supported FortiManager branch from 6.2 through 7.6 and four FortiManager Cloud branches are affected, meaning any organization using these products as the central management plane for FortiGate firewalls is exposed, and compromise of the appliance can provide a foothold across the entire managed firewall estate. The flaw was exploited as a zero-day in an active campaign before patches were available, was added to CISA KEV on 2024-10-23 (ransomware use not yet confirmed), and carries a 95.1% EPSS probability of exploitation within 30 days. Do: Upgrade FortiManager and FortiManager Cloud to the fixed releases listed in Fortinet advisory FG-IR-24-423 (FortiManager 7.6.1+, 7.4.5+, 7.2.8+, 7.0.13+, 6.4.15+, or 6.2.13+; Cloud 7.4.5+, 7.2.8+, 7.0.13+, or 6.4.8+), or apply the interim mitigations of restricting which IP addresses may connect to the fgfm service, disabling fgfm where it is not required, and applying the vendor's IPS signature. Hunt logs for signs of exploitation, such as unexpected fgfm requests, unknown IPs, or unexplained device registrations on the FortiManager. As a CISA KEV entry, federal agencies and other CISA-directed organizations must apply the mitigations or discontinue use of the product by the required deadline. | 9.8 | 95% | KEV PoC |
| moderate≈5,000 internet-exposed FortiManager/Cloud instances (order of thousands); total on-prem deployments likely higher |
Full article723 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The most consequential cyberattacks observed by Darktrace last year were linked to software defects in firewalls and perimeter network technologies.
Listen to this article
0:00
Learn more.
Edge devices harboring zero-day and n-day vulnerabilities were linked to the most consequential attack campaigns last year, Darktrace said in an annual threat report released Wednesday.
Darktrace’s threat researchers found the most frequent vulnerability exploits in customers’ instances of Ivanti Connect Secure and Ivanti Policy Secure appliances, along with firewall products from Fortinet and Palo Alto Networks.
Cybersecurity vendors shipped products that ultimately accounted for and became the initial access vector for the majority of the most significant attack campaigns last year, the report shows.
Vendors that supply security hardware and services were responsible for four of the six mostly commonly exploited vulnerabilities observed by Darktrace: a pair of vulnerabilities affecting Ivanti products (CVE-2023-46805 and CVE-2024-21887); a trio impacting Palo Alto Networks firewalls running PAN-OS (CVE-2024-3400, CVE-2024-0012 and CVE-2024-9474); and a vulnerability affecting Fortinet’s network management tool FortiManager (CVE-2024-47575).
“These devices sit on the edge of your network, and that’s your last sight of visibility and therefore the door to your house,” Nathaniel Jones, VP of threat research at Darktrace, told CyberScoop.
“If they can get through cybersecurity companies then they’re bypassing the exact detection that companies have provided customers,” Jones said. “You’re kind of getting underneath the specific thing that’s supposed to be detecting you, and getting access that way.”
Threat groups are increasingly investing more resources to study and reverse engineer network edge devices that are widespread. This shows up in Darktrace’s research, which complements the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog, particularly as it relates to repeat offenders — vendors that commonly appear on the agency’s continuously updated resource of vulnerabilities that threat groups have exploited in the wild.
Nation-state threat groups are most likely responsible for zero-day attacks on network edge devices because they have the resources, but these vulnerabilities have a long shelf life and are routinely targeted by financially motivated threat groups as proof of concepts emerge, Jones said.
“Your time to do patch management and get that closed off is just decreased, so it makes it challenging to manage those CVEs in these specific devices in a very quick timeframe,” Jones said. “If you’re not on it, or you’re very underresourced and you have other things going on to support the business, then this can be a problem.”
Threat actors also target edge devices because they provide greater capabilities to use living-off-the-land techniques and grab a compromised credential or create another credential to gain persistent access and achieve lateral movement across networks.
Forty percent of the malicious activity observed by Darktrace researchers in the first half of last year involved the exploitation of internet-facing devices. Information-stealing malware surged and became the most prominent activity observed by Darktrace in the second half of 2024.
Darktrace’s annual threat intelligence report on active threats in 2024 is based on research it gathered across its fleet of nearly 10,000 customer deployments.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/edge-device-vulnerabilities-fuel-attack-sprees/