Hackers go after SonicWall email appliances with three zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-20021 +1 in the same advisory: …20022 | Improper Privilege Management in SonicWall Email Security 10.0.9.x Grants Admin Access CVE-2021-20021 is an improper privilege management flaw (CWE-269) in SonicWall Email Security version 10.0.9.x. An unauthenticated remote attacker can trigger it by sending a crafted HTTP request to the vulnerable host, which allows the attacker to create a new administrative account on the Email Security instance. That administrative access gives an attacker full control over the email security platform (CVSS 9.8 with high confidentiality, integrity, and availability impact), enabling persistence, manipulation of email filtering, and a foothold from which to target downstream mail infrastructure. Any organization running SonicWall Email Security 10.0.9.x is affected, whether on hardware appliances (3300, 4300, 5050, 7050, 8300, 9000, 5000, 7000), as a virtual appliance, or via the hosted service. The flaw is being actively exploited in the wild: it was added to CISA's KEV on 2021-11-03 with known ransomware use (headlines tie SonicWall email appliance attacks to the HelloKitty gang), and EPSS estimates an 83.4% probability of exploitation within 30 days (100th percentile). Do: Upgrade SonicWall Email Security from 10.0.9.x to the latest patched release per SonicWall's instructions, as required by CISA KEV. Audit the deployment for unrecognized administrative accounts created by attackers, review management-interface HTTP logs for suspicious requests, and restrict exposure of the management interface to trusted networks. Because this bug was one of three SonicWall zero-days actively exploited with known ransomware use (HelloKitty), also hunt for signs of compromise and follow-on ransomware activity. | 9.8 group max | 83% | KEV ransomware |
| large≈ tens of thousands of deployments (order of 10k–100k systems) | |
| CVE-2021-20023 | Post-Auth Path Traversal Arbitrary File Read in SonicWall Email Security 10.0.9.x CVE-2021-20023 is a path traversal flaw (CWE-22) in SonicWall Email Security version 10.0.9.x that allows an attacker who has already authenticated to the product to read arbitrary files on the remote host via a crafted request. Because it is network-exploitable, requires only high-privileged (admin-level) credentials, and needs no user interaction, it is typically triggered with an administrator account or credentials compromised by an attacker. Successful exploitation exposes sensitive file contents, potentially including configuration data or credentials that enable follow-on compromise, and CISA notes known ransomware use. It affects organizations running SonicWall Email Security on hardware appliances (3300, 4300, 8300, 5000, 7000, 5050, 7050, 9000), the virtual appliance, and the hosted service. The flaw is being actively exploited: it was added to the CISA KEV on 2021-11-03 and headlines describe it as one of three zero-days actively exploited in SonicWall Email Security products in the wild. Do: Upgrade all Email Security deployments (hardware appliances, virtual appliance, hosted) off the vulnerable 10.0.9.x line to SonicWall's patched release per the vendor's instructions. Because exploitation requires authenticated admin access, restrict the management interface to trusted admin networks or VPN, review and rotate administrator credentials, and check for signs of compromise (unexpected admin logins, unusual file reads) given the known ransomware use. Prioritize patching internet-reachable appliances, as the flaw is listed in the CISA KEV and federal remediation is required. | 4.9 | 51% | KEV ransomware |
| largeroughly tens of thousands of appliance/virtual-appliance deployments plus hosted tenants (order-of-magnitude estimate) |
Full article611 words · extracted from therecord.media · click to collapse
A hacking group has used three zero-day vulnerabilities impacting SonicWall products to breach corporate networks and install backdoors, security firm FireEye said in a report on Tuesday. The attacks were first discovered in March 2021 by FireEye analysts responding to a security incident at one of their customers. The US security firm said the attacks used three previously unknown vulnerabilities —known as zero-days— to target SonicWall ES, an email security appliance that companies use in a cloud-hosted or on-premises format to scan email traffic for security threats. The attackers, which FireEye said it was tracking under a codename of UNC2682, used the three zero-days to bypass authentication (CVE-2021-20021), read sensitive files on the device (CVE-2021-20023), and modify local files or upload web shells which they could use as backdoors (CVE-2021-20022). FireEye said the attackers used the three zero-days in different combinations to achieve their goals. Standard UNC2682 attacks typically involved the hackers accessing a SonicWall ES appliance to create a new admin account or dump passwords for existing users. The attackers also extracted files from the SonicWall ES devices that contained details about existing accounts, including Active Directory credentials used by the application to connect to the local network. As a final step, the threat actors then uploaded a version of the BEHINDER JSP web shell in the appliance's built-in Tomcat Java web server, which they used to run commands on the underlying operating system, commands that allowed UNC2682 to collect additional details about the hacked company's internal network. FireEye explains: We observed the adversary executing the reg save command to dump the HKLM\SAM, HKLM\SYSTEM, and HKLM\SECURITY registry hives, which contain vital information in recovering password hashes and LSA secrets. Additionally, the adversary obtained in-memory sensitive credentials through the use of built-in memory dumping techniques. The adversary was observed invoking the MiniDump export of the Windows DLL comsvcs.dll to dump both the process memory for lsass.exe and the running instance of Apache Tomcat. FireEye said that the collected data was used after a few days for the attacker to attempt to move inside the victim's network. SonicWall released patches for affected appliances last week on April 13. At the time, the company did not release any information about the nature or severity of these issues, which drew criticism from device owners. It was only on Tuesday, April 20, a full week later, that SonicWall finally came forward to reveal that the three bugs it patched a week earlier had been actively exploited in the wild, a small detail that many system administrators would have most likely wanted to know a week earlier in order to prioritize patching. This is the second time this year that SonicWall has botched the response to zero-day vulnerabilities exploited in its products. In late January 2021, the company previously disclosed that it was itself hacked using a zero-day in its Secure Mobile Access (SMA) gateways. A week later, security firm NCC Group detected threat actors exploiting a mysterious SonicWall zero-day in its SMA devices. At the time, SonicWall wasn't even able to tell if the two zero-days were the same, as pointed out by infosec podcast Risky Business. Currently, SonicWall has advised all ES appliance owners that it is "imperative" to apply the latest patches.UNC2682 abused three SonicWall zero-days to plant web shells
SonicWall faces criticism for another botched response
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/hackers-go-after-sonicwall-email-appliances-with-three-zero-days