ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Week in review: Zero-click flaw in Synology NAS devices, Google fixes exploited Android vulnerability

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-10443
Unauthenticated OS Command Injection RCE in Synology Photos and BeePhotos

CVE-2024-10443 is an OS command injection flaw (CWE-78) in the Task Manager component of Synology Photos and Synology BeePhotos that allows remote, unauthenticated attackers to execute arbitrary code on the NAS via unspecified vectors. Because the vector requires no privileges and no user interaction (AV:N/PR:N per the CVSS 9.8 score), press coverage describes it as a zero-click RCE affecting internet-facing Synology NAS devices. An attacker who successfully exploits it gains full code execution on the device, typically with access to data stored on the NAS. Users running Synology Photos before 1.6.2-0720 / 1.7.0-0795 or BeePhotos before 1.0.2-10026 / 1.1.0-10053 are affected. Exploitation has not been confirmed in the wild and no public proof-of-concept is known, but the high EPSS score (28% within 30 days, 98th percentile) indicates a high predicted risk of imminent exploitation.

Do: Upgrade Synology Photos to 1.6.2-0720 or 1.7.0-0795 (or later) and BeePhotos to 1.0.2-10026 or 1.1.0-10053 (or later) as soon as possible. Until patched, limit exposure by disabling external/QuickConnect access to the Photos/BeePhotos services and removing port-forwarding rules to the NAS web interface. Check DSM logs for unexpected processes or network connections, and inventory all NAS units, since exploitation requires no authentication or user interaction.

9.828%
  • Synology Photos all versions before 1.6.2-0720 (1.6.x line) and before 1.7.0-0795 (1.7.x line)
  • Synology BeePhotos all versions before 1.0.2-10026 (1.0.x line) and before 1.1.0-10053 (1.1.x line)
massmillions of NAS devices (press reports cite millions of vulnerable Synology DiskStation and BeePhotos units)
CVE-2024-20418
A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Poi

A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with root privileges on the underlying operating system. This vulnerability is due to improper validation of input to the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the underlying operating system of the affected device.

NVD description · AI analysis pending
10.03%
CVE-2024-43047
Use-After-Free in Qualcomm FastConnect and QCA Chipset Firmware

CVE-2024-43047 is a use-after-free vulnerability (CWE-416) in the firmware of several Qualcomm connectivity chipsets and the QAM8295P automotive SoC, where maintaining memory maps of high-level operating system (HLOS) memory causes memory corruption. The flaw is scored with a local attack vector and low privileges required (CVSS 3.1: 7.8), so an attacker needs some local foothold, such as a malicious app on an Android device, and can then leverage the memory corruption for high-impact confidentiality, integrity, and availability effects, in practice a privilege escalation to system or kernel level. Anyone running devices built on the affected chips is exposed, including Android smartphones with FastConnect 6700/6800/6900/7800, devices using QCA-series Wi-Fi chips, and automotive platforms using the QAM8295P. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-08, and news reports describe targeted, limited Android attacks, though ransomware use is unknown and EPSS remains modest at 0.7%.

Do: Apply Qualcomm's fix through your device or system OEM: install the latest Android security updates on affected phones, and update firmware/drivers for QCA-series Wi-Fi chips and the QAM8295P automotive SoC per vendor instructions; because this is a local firmware flaw, there is no user-side mitigation short of patching. Organizations under CISA KEV must remediate per the required action (apply vendor remediations or discontinue use). Prioritize an inventory of Android devices with FastConnect 6700/6800/6900/7800 and QCA6xxx/65xxx chips, noting this flaw is being used in targeted attacks rather than mass-scale campaigns.

7.8<1% KEV
  • qualcomm fastconnect 6700 firmware
  • qualcomm fastconnect 6800 firmware
  • qualcomm fastconnect 6900 firmware
  • +9 more
massplausibly hundreds of millions of devices (affected Qualcomm FastConnect and QCA connectivity chips ship across Android smartphones, PCs with Qualcomm Wi-Fi…
CVE-2024-43093
Local Privilege Escalation via Unicode Path Filter Bypass in Android Framework

CVE-2024-43093 is a privilege escalation flaw in the Android Framework's ExternalStorageProvider (the component behind the system document/file picker), where the shouldHideDocument function mishandles Unicode normalization, allowing crafted file paths to bypass the filter that hides sensitive directories such as app-private storage (CWE-176). It is triggered locally: an app with no additional execution privileges can exploit it with user interaction, for example when a user selects a file or location through the documents UI. A successful bypass grants unauthorized access to otherwise protected directories and can lead to local escalation of privilege with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.3, vector AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Any device running the Android Framework is in scope, meaning effectively the entire Android installed base, although the local access and user-interaction requirements limit practical exploitability to targeted scenarios. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-07 and Google has indicated it may be under limited, targeted exploitation; no public proof-of-concept is known, and EPSS currently rates the 30-day exploitation probability at a modest 0.7%, though the KEV listing is the authoritative in-the-wild signal.

Do: Apply Google's Android security updates immediately — the fix is included in the November 2024 Android Security Bulletin (security patch level 2024-11-01) or later — and verify the device's security patch level in Settings; OEM devices (e.g., Samsung) may receive the fix through vendor updates on a lag. Per the CISA KEV required action, treat patching as urgent or apply vendor mitigations, and as an interim measure restrict sideloaded/untrusted app installs and caution users when picking files through the document picker. Ransomware linkage is unknown, and the user-interaction requirement means exploitation is targeted rather than wormable.

7.3<1% KEV
  • Google Android (Android Framework component)
massbillions of Android devices worldwide (Android runs on roughly 70% of global smartphones)
CVE-2024-5910
Unauthenticated Admin Account Takeover in Palo Alto Networks Expedition

CVE-2024-5910 is a missing authentication flaw (CWE-306) in Palo Alto Networks Expedition, a tool used to migrate, tune, and enrich firewall configurations. An attacker with network access to an Expedition instance can exploit the unauthenticated critical function to take over the Expedition admin account without any credentials. Once in control, the attacker can access configuration secrets, credentials, and other data imported into Expedition, and public research (horizon3.ai) shows it can be chained with other Expedition bugs for full system compromise. Any organization running Expedition — particularly instances reachable from the internet or shared networks — is affected. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-07, carries a 91.8% EPSS exploitation probability, and is being exploited alongside related Expedition and firewall bugs (CVE-2024-9463, CVE-2024-9465).

Do: Apply the vendor's patched Expedition release per Palo Alto Networks' advisory; if the tool is no longer needed, decommission or discontinue it, as CISA permits. Until patched, restrict network access to Expedition to trusted management hosts and remove it from internet exposure. Check Expedition logs for signs of unauthorized admin access and rotate any credentials or secrets stored in the tool.

9.392% KEV PoC
  • Palo Alto Networks Expedition
nichelikely low thousands of deployments worldwide; unknown for internet-exposed instances
Full article951 words · extracted from helpnetsecurity.com · click to collapse

Week in review

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Millions of Synology NAS devices vulnerable to zero-click attacks (CVE-2024-10443)
Synology has released fixes for an unauthenticated “zero-click” remote code execution flaw (CVE-2024-10443, aka RISK:STATION) affecting its popular DiskStation and BeeStation network attached storage (NAS) devices.

Google patches actively exploited Android vulnerability (CVE-2024-43093)
Google has delivered fixes for two vulnerabilities endangering Android users that “may be under limited, targeted exploitation”: CVE-2024-43047, a flaw affecting Qualcomm chipsets, and CVE-2024-43093, a vulnerability in the Google Play framework.

How AI will shape the next generation of cyber threats
In this Help Net Security interview, Buzz Hillestad, CISO at Prismatic, discusses how AI’s advancement reshapes cybercriminal skillsets and lowers entry barriers for potential attackers.

Critical Palo Alto Networks Expedition bug exploited (CVE-2024-5910)
A vulnerability (CVE-2024-5910) in Palo Alto Networks Expedition, a firewall configuration migration tool, is being exploited by attackers in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Thursday.

Industrial companies in Europe targeted with GuLoader
A recent spear-phishing campaign targeting industrial and engineering companies in Europe was aimed at saddling victims with the popular GuLoader downloader and, ultimately, a remote access trojan that would permit attackers to steal information from and access compromised computers whenever they wish.

The cybersecurity gender gap: How diverse teams improve threat response
In this Help Net Security interview, Julie Madhusoodanan, Head of Cybersecurity – Identity, Posture Management and Security Infrastructure at LinkedIn, discusses how closing the gender gap could enhance cybersecurity’s effectiveness in combating emerging threats.

North Korean hackers employ new tactics to compromise crypto-related businesses
North Korean hackers are targeting crypto-related businesses with phishing emails and novel macOS-specific malware.

Maximizing security visibility on a budget
In this Help Net Security interview, Barry Mainz, CEO at Forescout, discusses the obstacles organizations encounter in attaining security visibility, particularly within cloud and hybrid environments.

Critical vulnerability in Cisco industrial wireless access points fixed (CVE-2024-20418)
Cisco has fixed a critical command injection vulnerability (CVE-2024-20418) affecting its Ultra-Reliable Wireless Backhaul (URWB) Access Points that can be exploited via a HTTP requests and allows complete compromise of the devices.

Hiring guide: Key skills for cybersecurity researchers
In this Help Net Security interview, Rachel Barouch, an Organizational Coach for VCs and startups and a former VP HR in both a VC and a Cybersecurity startup, discusses the dynamics of cybersecurity researchers and team-building strategies.

All Google Cloud users will have to enable MFA by 2025
Google has announced that, by the end of 2025, multi-factor authentication (MFA) – aka 2-step verification – will become mandatory for all Google Cloud accounts.

Am I Isolated: Open-source container security benchmark
Am I Isolated is an open-source container security benchmark that probes users’ runtime environments and tests for container isolation.

GoZone ransomware accuses and threatens victims
A new ransomware dubbed GoZone is being leveraged by attackers that don’t seem to be very greedy: they are asking the victims to pay just $1,000 in Bitcoin if they want their files decrypted.

Whispr: Open-source multi-vault secret injection tool
Whispr is an open-source CLI tool designed to securely inject secrets from secret vaults, such as AWS Secrets Manager and Azure Key Vault, directly into your application’s environment.

Beware of phishing emails delivering backdoored Linux VMs!
Unknown attackers are trying to trick Windows users into spinning up a custom Linux virtual machine (VM) with a pre-configured backdoor, Securonix researchers have discovered.

Apple’s 45-day certificate proposal: A call to action
In a bold move, Apple has published a draft ballot for commentary to GitHub to shorten Transport Layer Security (TLS) certificates down from 398 days to just 45 days by 2027.

A closer look at the 2023-2030 Australian Cyber Security Strategy
In this Help Net Security video, David Cottingham, CEO of Airlock Digital, discusses the 2023-2030 Australian Cyber Security Strategy and reviews joint and individual cybersecurity efforts, progress, and strategies over the past year.

Identity-related data breaches cost more than average incidents
Identity-related data breaches are more severe and costly than run-of-the-mill incidents, according to RSA.

Consumer privacy risks of data aggregation: What should organizations do?
This article breaks down key privacy challenges and offers practical guidance to help organizations safeguard consumer data in today’s complex digital landscape.

Key cybersecurity predictions for 2025
In this Help Net Security video, Chris Gibson, CEO at FIRST, discusses the evolving threat landscape and provides a unique take on where data breaches and cyber attacks will be in 2025.

Osmedeus: Open-source workflow engine for offensive security
Osmedeus is an open-source workflow engine designed for offensive security. It serves as a versatile foundation, enabling users to easily create customized reconnaissance systems and scale them across extensive target lists.

Open-source software: A first attempt at organization after CRA
The open-source software (OSS) industry is developing the core software for the global infrastructure, to the point that even some proprietary software giants adopt Linux servers for their cloud services.

Cybersecurity in crisis: Are we ready for what’s coming?
In this Help Net Security video, James Edgar, CISO at Corpay, reveals insights into cybersecurity health, concerns, challenges, and other considerations for building a solid defense program.

Cybersecurity jobs available right now: November 5, 2024
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.

Report: Voice of Practitioners 2024 – The True State of Secrets Security
In this study, GitGuardian and CyberArk reveal the stark reality of secrets management across 1,000 organizations.

New infosec products of the week: November 8, 2024
Here’s a look at the most interesting products from the past week, featuring releases from Atakama, Authlete, Symbiotic Security, and Zywave.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/11/10/week-in-review-zero-click-flaw-in-synology-nas-devices-google-fixes-exploited-android-vulnerability/