US CISA added critical Apache RocketMQ flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-33246 | Unauthenticated Remote Command Execution in Apache RocketMQ CVE-2023-33246 is an unauthenticated remote command execution flaw in Apache RocketMQ: when NameServer, Broker, or Controller components are exposed without access controls, an attacker can invoke the update-configuration function or forge RocketMQ protocol messages to inject and run operating-system commands. Commands execute with the privileges of the system user running RocketMQ, giving an attacker full control of the message broker host. Any organization running RocketMQ 5.1.0 or below (5.x) or versions below 4.9.6 (4.x) with these components reachable by untrusted networks is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-06, carries a 96.6% EPSS probability of exploitation, has multiple public PoC exploits, and is being leveraged by the Muhstik botnet to expand DDoS operations alongside other malware campaigns. Do: Upgrade to RocketMQ 5.1.1 or above for 5.x deployments, or 4.9.6 or above for 4.x, per the KEV required action. Until patched, restrict NameServer, Broker, and Controller ports to trusted clients only and avoid exposing them to the internet without authentication or access filtering. Check patched hosts for signs of compromise (unauthorized processes, cron jobs, or botnet activity such as Muhstik), since active exploitation is documented. | 9.8 | 97% | KEV PoC ×4 |
| largeTens of thousands of internet-exposed instances plausible (thousands confirmed in public scans; total installed base larger, exact count unknown) |
Full article430 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 09, 2023

US CISA added critical vulnerability CVE-2023-33246 in Apache RocketMQ to its Known Exploited Vulnerabilities catalog.
US Cybersecurity and Infrastructure Security Agency (CISA) added a critical flaw CVE-2023-33246 (CVSS score 9.8) affecting Apache RocketMQ to its Known Exploited Vulnerabilities Catalog.
Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. Threat actors could exploit this vulnerability to execute arbitrary commands as the system users that RocketMQ is running. An attacker can trigger the flaw by using the update configuration function or by forging the RocketMQ protocol content
The vulnerability impacts Apache RocketMQ 5.1.0 and below, users are recommended to upgrade to version 5.1.1 above for using RocketMQ 5.x or 4.9.6 above for using RocketMQ 4.x .
The Apache’s advisory was published on May, but CISA added the issue to the Known Exploited Vulnerabilities Catalog after cybersecurtiy firm VulnCheck published technical details for the vulnerability.
“CVE-2023-33246 is an easy to exploit vulnerability affecting Apache RocketMQ. The vulnerability allows a remote and unauthenticated attacker to update the RocketMQ broker configuration in order to abuse a command injection.” reads the analysis published by VulnCheck. “Juniper Networks has reported exploitation of this issue has been ongoing since June 2023.”
VulnCheck’s lead threat researcher @Junior_Baines examines RocketMQ CVE-2023-33246 compromises in the wild. The analysis reveals a variety of malicious payloads and includes a small sampling of associated IP addresses and malware hashes. Learn more: https://t.co/mqTBJF6MZt
— VulnCheck (@VulnCheckAI) September 5, 2023
The researchers pointed out that exploitation occurs via a custom remoting protocol to the RocketMQ broker ports (by default 10909 and 10911). Both Shodan or Censys are not able to detect this protocol, making it hard to determine the actual scope of vulnerable systems in the wild.
The researchers explained that CVE-2023-33246 is only associated with one botnet, however, they believe that at least a few active threat actors are actively exploiting the issue in the wild. Experts recommend removing RocketMQ instance from the internet and examining the broker configuration for signs of exploitation.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this flaw by September 27, 2023.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/150551/hacking/cisa-apache-rocketmq-known-exploited-vulnerabilities-catalog.html