ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

FBI: Barracuda Appliances Still Being Exploited By China

criticalExploit / PoCimportance 60CVE-2023-2868

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-2868
Unauthenticated Command Injection in Barracuda Email Security Gateway Appliances via .tar Files

CVE-2023-2868 is a critical (CVSS 9.8) remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) appliance form factor (models 300, 400, 600, 800 and 900), caused by incomplete input validation of user-supplied .tar archives, specifically the names of the files contained within them. An attacker can deliver a specially crafted .tar file whose internal file names are formatted so that, when the ESG processes the archive, commands are executed through Perl's qx operator. Successful exploitation yields remote command execution with the privileges of the ESG product, and in the observed campaign attackers deployed a backdoor (reported as "SUBMARINE") and persisted on compromised appliances. Only customers running ESG appliances on versions 5.1.3.001 through 9.2.0.006 are affected. Exploitation is confirmed in the wild — CISA added it to the KEV on 2023-05-26, EPSS puts 30-day exploitation probability at 87.7%, and public reporting attributes active exploitation to a Chinese-nexus espionage group (associated in headlines with Salt Typhoon) targeting government, military, and telecom victims; Barracuda's BNSF-36456 patch was applied automatically to customer appliances.

Do: Verify that each ESG appliance received the automatic BNSF-36456 patch (running fixed firmware at or above 9.2.0.006's successor per vendor instructions), and check appliances for indicators of compromise, including unauthorized command activity and the "SUBMARINE" backdoor, using Barracuda's IOC guidance. Because the espionage campaign established persistence, Barracuda urged full replacement rather than patching of compromised appliances; replace any ESG showing signs of compromise and review email logs for malicious .tar attachments. Limit or monitor internet exposure of ESG management interfaces while remediation proceeds.

9.888% KEV
  • Barracuda Networks Email Security Gateway (ESG) 300 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 400 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 600 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • +2 more
largetens of thousands of deployed ESG appliances (public scans show Barracuda ESGs among commonly internet-exposed email security devices); Barracuda's incident…
Full article402 words · extracted from infosecurity-magazine.com · click to collapse

The FBI has urged users of affected Barracuda appliances to replace them immediately, after warning that they’re still being targeted by a Chinese APT group.

A Flash update issued by the agency this week revealed that zero-day vulnerability CVE-2023-2868 continues to be exploited by the group, dubbed UNC4841 by Mandiant, in cyber-espionage attacks.

“Barracuda customers should remove all ESG appliances immediately. The patches released by Barracuda in response to this CVE were ineffective,” the alert noted.

“The FBI continues to observe active intrusions and considers all affected Barracuda ESG appliances to be compromised and vulnerable to this exploit. In addition, customers should further investigate for any further compromise by conducting scans for outgoing connections using the list of indicators provided as the malicious cyber actors have demonstrated the ability to compromise email accounts and computer networks, as well as maintain persistence in victim networks for continued future operations and data exfiltration.”

On June 6, Barracuda Networks took the unusual step of urging customers to isolate and replace their Email Security Gateway (ESG) appliances, whatever their patch status, after it became clear that its attempts to patch the zero-day bug weren’t working.

Read more on the Barracuda attacks: Barracuda Urges Swift Replacement of Vulnerable ESG Appliances

The APT group linked to China has been able to switch malware and deploy new persistence mechanisms to maintain access.

“Based on the FBI’s investigation to date, the cyber actors exploited this vulnerability in a significant number of ESG appliances and injected multiple malicious payloads that enabled persistent access, email scanning, credential harvesting, and data exfiltration,” the FBI explained.

“In many cases, the cyber actors obfuscated their actions with counter-forensic techniques, making detection of compromise difficult through only scanning the appliance itself for indicators of compromise. As a result, it is imperative that networks scan various network logs for connections to any of the listed indicators.”

The FBI urged Barracuda ESG customers to:

  • Review email logs to identify the initial point of exposure
  • Revoke and rotate all domain-based and local credentials that were on the ESG at the time of compromise
  • Revoke and reissue all certificates that were on the ESG at the time of compromise
  • Monitor the entire network for the use of credentials that were on the ESG at the time of compromise
  • Review network logs for signs of data exfiltration and lateral movement
  • Capture forensic image of the appliance and conduct a forensic analysis

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/barracuda-appliances-exploited/