ZeroHour
Security Affairspublished ()ingested @securityaffairs

Multiple APT groups are exploiting VPN vulnerabilities, NSA warns

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-13379
Unauthenticated Path Traversal in Fortinet FortiOS SSL VPN

CVE-2018-13379 is a path traversal flaw (CWE-22) in the Fortinet FortiOS SSL VPN web portal that allows an unauthenticated attacker to download FortiOS system files via specially crafted HTTP resource requests. By traversing directories through crafted requests to the exposed web portal, the attacker can retrieve sensitive files, a technique publicly documented as yielding the SSL VPN session file containing usernames and passwords in plaintext. Any organization running the SSL VPN web portal on a FortiGate appliance is affected, and risk is highest where the portal is directly reachable from the internet. The flaw is confirmed in the wild: it was added to the CISA KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days. No public PoC is listed in the provided data, but credential theft tied to this bug has been widely reused by threat actors.

Do: Apply the patched FortiOS release per Fortinet's vendor advisory immediately, as this is a CISA KEV required action; if the fixed version is not known from this data, follow Fortinet's FG-IR-18-384 advisory for the correct upgrade path. Rotate SSL VPN credentials and review VPN access logs for path-traversal requests, since successful exploitation exposes plaintext session credentials, and restrict SSL VPN portal exposure to trusted sources where possible.

9.8100% KEV ransomware
  • Fortinet FortiOS
mass≈500,000 internet-exposed FortiOS SSL VPN portals (Fortinet cited ~480,000 affected devices)
CVE-2018-13382
Unauthenticated SSL VPN Account-Takeover Flaw in Fortinet FortiOS and FortiProxy

CVE-2018-13382 is an improper authorization flaw (CWE-863) in the SSL VPN web portal of Fortinet FortiOS and FortiProxy that fails to properly authorize password-change requests. An unauthenticated attacker who can reach the SSL VPN web portal can send specially crafted HTTP requests to modify the password of an SSL VPN web-portal user without knowing the existing credentials. This effectively hands the attacker control of the victim's VPN account, enabling login through the portal and potential follow-on access to the internal network, consistent with the integrity-only CVSS 3.1 score of 7.5 (High). Any organization running affected versions - FortiOS 6.0.0-6.0.4, 5.6.0-5.6.8 or 5.4.1-5.4.10, or FortiProxy 2.0.0, 1.2.0-1.2.8, 1.1.0-1.1.6 or 1.0.0-1.0.7 - with the SSL VPN web portal enabled is affected. The flaw is actively exploited: it was added to CISA's KEV catalog on 2022-01-10 with known ransomware use, EPSS estimates an 81.7% probability of exploitation within 30 days, and NSA/NCSC advisories warn that APT groups are exploiting VPN vulnerabilities of this kind.

Do: Apply updates to all affected FortiOS and FortiProxy deployments per Fortinet's instructions, as this is the CISA KEV required action, prioritizing internet-facing SSL VPN portals. Until patched, limit exposure of the SSL VPN web portal and audit authentication logs for unexpected password changes or unauthenticated requests to the portal. Given known ransomware and APT exploitation, force a password reset on VPN accounts whose credentials may have been tampered with.

7.582% KEV ransomware
  • Fortinet FortiOS 6.0.0-6.0.4, 5.6.0-5.6.8, 5.4.1-5.4.10
  • Fortinet FortiProxy 2.0.0, 1.2.0-1.2.8, 1.1.0-1.1.6, 1.0.0-1.0.7
masshundreds of thousands of internet-exposed FortiGate/FortiProxy SSL VPN endpoints (estimate)
CVE-2018-13383
Out-of-Bounds Write in Fortinet FortiOS and FortiProxy SSL VPN Web Service

CVE-2018-13383 is a heap buffer overflow (out-of-bounds write, CWE-787) in the SSL VPN web portal of Fortinet FortiOS and FortiProxy. It is triggered when a logged-in SSL VPN user's web session processes crafted JavaScript supplied by a remote site, corrupting heap memory in the SSL VPN web service. An attacker can crash the SSL VPN web service, terminating access for logged-in users, and Fortinet's advisory indicates the memory corruption may allow arbitrary code execution via a crafted JavaScript payload. Organizations running affected FortiOS releases on FortiGate appliances with the SSL VPN web portal enabled, and organizations running FortiProxy secure web gateways, are affected. Exploitation is active: the flaw was added to CISA KEV on 2022-01-10 with known ransomware use, the required action is to apply vendor updates, and EPSS assigns a 33.6% 30-day exploitation probability (98th percentile).

Do: Apply Fortinet's fixed releases per the vendor advisory (FortiGate/FortiOS: 6.2.1+, 6.0.5+, 5.6.8+, or 5.4.11+ as applicable; FortiProxy: 2.0.1+ or 1.2.9+), consistent with the CISA KEV required action. Until patched, restrict exposure of the SSL VPN web portal to the internet and monitor the appliance for signs of compromise, given the known ransomware use. Prioritize internet-facing SSL VPN endpoints in remediation ordering because of the elevated EPSS score.

6.534% KEV ransomware
  • Fortinet FortiOS Multiple releases including 6.2.0, 6.0.0-6.0.4, 5.6.0-5.6.7, and 5.4.0-5.4.10 (ranges per Fortinet advisory; source data does not specify versions)
  • Fortinet FortiProxy 2.0.0 and 1.2.x releases (ranges per Fortinet advisory; source data does not specify versions)
masslikely several hundred thousand internet-exposed FortiGate SSL VPN portals and FortiProxy gateways, out of a Fortinet installed base in the millions of devices
CVE-2019-11510
Unauthenticated Arbitrary File Read in Ivanti Pulse Connect Secure VPN

Ivanti Pulse Connect Secure, an enterprise SSL VPN appliance, contains an arbitrary file read vulnerability (CWE-22, path traversal) that requires no authentication. An unauthenticated remote attacker with network access to the appliance over HTTPS can send a specially crafted URI containing traversal sequences to read arbitrary files from the device. The attacker gains access to sensitive appliance files, potentially including configuration or credential material useful for further compromise, and CISA records known ransomware use of this flaw. Any organization running Pulse Connect Secure, especially gateways exposed to the internet for remote access, is affected. Exploitation is established: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, EPSS assigns a 100% probability of exploitation in the next 30 days, and no public PoC is known.

Do: Apply updates per Ivanti's instructions, the required action in the CISA KEV entry, prioritizing internet-facing Pulse Connect Secure gateways, and consult the vendor advisory for the applicable fixed release since no version range is provided here. Where patching is not immediate, restrict HTTPS access to the appliance and hunt for signs of exploitation (unexpected file reads, anomalous VPN logins or sessions, and follow-on ransomware activity), as CISA reports known ransomware use.

10.0100% KEV ransomware PoC ×2
  • Ivanti Pulse Connect Secure
largeTens of thousands of internet-exposed gateways (order of 10,000-100,000 systems; each typically serves hundreds of VPN users, so potentially millions of users)
CVE-2019-11539
Authenticated Command Injection in Ivanti Pulse Connect Secure and Policy Secure

Ivanti/Pulse Secure Pulse Connect Secure and Pulse Policy Secure contain an OS command injection flaw (CWE-78) in the admin web interface. An authenticated attacker can send crafted requests to the administrative web interface to inject and execute arbitrary operating-system commands on the appliance. Successful exploitation gives full control of the VPN or network access control appliance, enabling data theft, persistence, and pivoting into the corporate intranet. Any organization running an affected Pulse Connect Secure (9.0RX/8.3RX/8.2RX/8.1RX) or Pulse Policy Secure (9.0RX/5.4RX/5.3RX/5.2RX/5.1RX) release is exposed, especially internet-facing VPN gateways. Exploitation is very active: the bug is in CISA's KEV, public research chained it with CVE-2019-11510 into an unauthenticated RCE chain, APT groups and Black Kingdom ransomware operators have been reported exploiting Pulse VPN flaws, and EPSS estimates a 98.5% probability of exploitation within 30 days.

Do: Upgrade Pulse Connect Secure to 9.0R3.4+ (or 8.3R7.1+, 8.2R12.1+, 8.1R15.1+) and Pulse Policy Secure/Policy Secure to 9.0R3.2+ (or 5.4R7.1+, 5.3R12.1+, 5.2R12.1+, 5.1R15.1+) per vendor instructions. Restrict exposure of the admin web interface to trusted networks, rotate administrative credentials, and hunt for signs of compromise on appliances that were internet-exposed, particularly where the chained CVE-2019-11510 file-read flaw may also have been exploited.

7.299% KEV ransomware PoC ×2
  • ivanti / pulsesecure Pulse Connect Secure 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, 8.1RX before 8.1R15.1
  • ivanti / pulsesecure Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, 5.1RX before 5.1R15.1
  • ivanti / pulsesecure Policy Secure Same ranges as Pulse Policy Secure (9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, 5.1RX before 5.1R15.1)
masson the order of 100,000 to several hundred thousand internet-exposed Pulse Connect Secure/Policy Secure appliances
CVE-2019-1579
Format String RCE in Palo Alto Networks PAN-OS GlobalProtect Portal/Gateway

CVE-2019-1579 is a remote code execution vulnerability (CWE-134, format string) in Palo Alto Networks PAN-OS that is exposed on devices where the GlobalProtect Portal or GlobalProtect Gateway interface is enabled. An attacker can trigger it remotely by sending specially crafted format-string input to the network-facing GlobalProtect portal or gateway interface. Successful exploitation allows arbitrary code execution on the firewall, giving the attacker control of the device and a foothold into the protected network. Any organization running PAN-OS with the GlobalProtect Portal or Gateway interface enabled is affected; deployments without those interfaces enabled are not exposed to this flaw. Exploitation is confirmed: the vulnerability is in CISA's KEV (added 2022-01-10) with known ransomware use, and EPSS assigns a 46.2% probability of exploitation within 30 days (99th percentile), although no public PoC is catalogued.

Do: Upgrade PAN-OS per Palo Alto Networks' security advisory, as required by CISA's KEV required action; first inventory devices with the GlobalProtect Portal or Gateway interface enabled and prioritize internet-facing ones. Until patched, restrict or firewall access to the GlobalProtect interfaces, and hunt for signs of compromise given the known ransomware association.

8.146% KEV ransomware PoC
  • Palo Alto Networks PAN-OS
largetens of thousands of internet-exposed GlobalProtect portals/gateways (likely more including internally deployed gateways)
Full article461 words · extracted from securityaffairs.com · click to collapse

NSA is warning of multiple state-sponsored cyberespionage groups exploiting enterprise VPN Flaws

Last week, the UK’s National Cyber Security Centre (NCSC) reported that advanced persistent threat (APT) groups have been exploiting recently disclosed VPN vulnerabilities in enterprise VPN products in attacks in the wild. Threat actors leverage VPN vulnerabilities in Fortinet, Palo Alto Networks and Pulse Secure, to breach into the target networks.

The UK agency reported that APT groups target several vulnerabilities, including CVE-2019-11510 and CVE-2019-11539 in Pulse Secure VPN solutions, and CVE-2018-13379,

The CVE-2018-13379 is a path traversal vulnerability in the FortiOS SSL VPN web portal that could be exploited by an unauthenticated attacker to download FortiOS system files. The CVE-2018-13379 flaw could be exploited to obtain administrator credentials in plain text.

The CVE-2019-11510 flaw in Pulse Connect Secure is a critical arbitrary file read vulnerability.

APT groups also exploit CVE-2018-13382, CVE-2018-13383, and CVE-2019-1579, in Palo Alto Networks products.

The vulnerabilities were first reported in July by researchers Orange Tsai and Meh Chang from DEVCORE that found several flaws in Fortinet, Palo Alto Networks and Pulse Secure products. The issues could be exploited by threat actors to access corporate networks and steal sensitive documents

Microsoft researchers recently reported that the APT5 cyberespionage group (aka MANGANESE) has been exploiting VPN vulnerabilities since July, some weeks before PoC exploits were publicly discosed.

Now NSA is warning of multiple state-sponsored cyberespionage groups exploiting enterprise VPN Flaws

“Multiple Nation State Advanced Persistent Threat (APT) actors have weaponized CVE-2019-11510, CVE-2019-11539, and CVE-2018-13379 to gain access to vulnerable VPN devices.” reads the security advisory published by the NSA.

“If a malicious actor previously exploited the vulnerability to collect legitimate credentials, these credentials would still be valid after patching. NSA recommends resetting credentials after a vulnerable VPN device is upgraded and before it is reconnected to the external network:

  • Immediately update VPN user, administrator, and service account credentials.
  • Immediately revoke and generate new VPN server keys and certificates. This may require redistributing VPN connection information to users.
  • If compromise is suspected, review accounts to ensure no new accounts were created by adversaries.”

Both NCSC or NSA intelligence agencies confirmed that APT groups targeted several sectors, including military, government, academic, business and healthcare. The security advisories published by the agencies did not name any APTs leveraging the above VPN vulnerabilities.

In August, BadPackets experts observed a mass scanning activity targeting Pulse Secure “Pulse Connect Secure” VPN endpoints vulnerable to CVE-2019-11510. At the time, over 14,000 vulnerable Pulse Secure endpoints were hosted by more than 2,500 organizations. The number of vulnerable endpoints dropped to roughky 6,000 by October 8, most of them in the United States, Japan and the UK.

https://twitter.com/bad_packets/status/1181610353542586368

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – VPN vulnerabilities, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/92310/apt/nsa-warns-apt-vpn-vulnerabilities.html