Pulse Secure VPNs Get New Urgent Update for Poorly Patched Critical Flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-8260 | Authenticated RCE in Ivanti Pulse Connect Secure admin web interface (pre-9.1R9) Ivanti Pulse Connect Secure versions before 9.1R9 contain a vulnerability (mapped to CWE-434) in the administrative web interface in which compressed uploads are handled with uncontrolled gzip extraction. An authenticated attacker with high-privilege (admin-level) access to that interface can send a crafted gzip-compressed file, triggering arbitrary code execution on the appliance with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.2, AV:N/PR:H). Successful exploitation yields arbitrary code execution on the VPN appliance itself, effectively enabling full compromise of the gateway that terminates the organization's VPN sessions. Any organization running Pulse Connect Secure on a release prior to 9.1R9 is affected, making the typical target an enterprise or government SSL VPN appliance accessible to anyone holding admin credentials. Exploitation is in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 96.5% EPSS exploitation probability (100th percentile), and a public proof of concept is available. Do: Upgrade Pulse Connect Secure to 9.1R9 or later per the vendor's instructions; given the related patch-bypass flaw CVE-2021-22937 and the 'new urgent update' headlines, ensure the most recent available 9.1R release is applied rather than relying solely on the original 9.1R9 fix. Restrict the admin web interface to trusted management networks and review administrative accounts. Because the flaw is on CISA's KEV list and CISA has published malware analysis reports for Pulse Secure-targeted samples, hunt patched and unpatched devices for signs of compromise (e.g., web shells or implants). | 7.2 | 96% | KEV PoC |
| mass≈10^5 devices: a six-figure installed base of Pulse Connect Secure appliances, with tens of thousands internet-exposed in public scans at the time of the 2021… | |
| CVE-2021-2293 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). NVD description · AI analysis pending | 4.9 | 1% |
| — | ||
| CVE-2021-22937 | A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploa A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface. NVD description · AI analysis pending | 7.2 | 8% |
| — |
Full article557 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananAug 09, 2021
Pulse Secure has shipped a fix for a critical post-authentication remote code execution (RCE) vulnerability in its Connect Secure virtual private network (VPN) appliances to address an incomplete patch for an actively exploited flaw it previously resolved in October 2020.
"The Pulse Connect Secure appliance suffers from an uncontrolled archive extraction vulnerability which allows an attacker to overwrite arbitrary files, resulting in Remote Code Execution as root," NCC Group's Richard Warren disclosed on Friday. "This vulnerability is a bypass of the patch for CVE-2020-8260."
"An attacker with such access will be able to circumvent any restrictions enforced via the web application, as well as remount the filesystem, allowing them to create a persistent backdoor, extract and decrypt credentials, compromise VPN clients, or pivot into the internal network," Warren added.
The disclosure comes days after Ivanti, the company behind Pulse Secure, published an advisory for as many as six security vulnerabilities on August 2, urging customers to move quickly to update to Pulse Connect Secure version 9.1R12 to secure against any exploitation attempts targeting the flaws.
Tracked as CVE-2021-22937 (CVSS score: 9.1), the shortcoming could "allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface," according to Pulse Secure. CVE-2020-8260 (CVSS core: 7.2), which concerns an arbitrary code execution flaw using uncontrolled gzip extraction, was remediated in October 2020 with version 9.1R9.
"CVE-2021-2293 is a separate vulnerability and is not a bypass of CVE-2020-8260, but is similar in terms of impact and vulnerability type, which is why we assigned a separate CVE," Daniel Spicer, Invanti's vice president of security, said in a statement to The Hacker News.
The vulnerability is due to a flaw in the way that archive files (.TAR) are extracted in the administrator web interface. While further checks were added to validate the TAR file to prevent exploitation of CVE-2020-8260, additional variant and patch analysis revealed that it's possible to exploit the same extraction vulnerability in the part of the source code that handles profiler device databases, effectively getting around the mitigations put in place.
"Whilst this issue was patched by adding validation to extracted files, this validation does not apply to archives with the 'profiler' type," Warren said. "Therefore, by simply modifying the original CVE-2020-8260 exploit to change the archive type to 'profiler', the patch can be bypassed, and code execution achieved."
It's worth noting that CVE-2020-8260 was one among the four Pulse Secure flaws that was actively exploited by threat actors earlier this April to stage a series of intrusions targeting defense, government, and financial entities in the U.S. and beyond in a bid to circumvent multi-factor authentication protections and breach enterprise networks. Given the possibility of real-world exploitation, it's highly recommended to upgrade to Pulse Connect Secure (PCS) 9.1R12, or later.
"A rigorous code review is just one of the steps we are taking to further bolster our security and protect our customers," Spicer said. "For instance, we are also further expanding our existing internal product security resources to ramp up the pace and intensity of testing on existing products as well as those of companies or systems that we integrate into Ivanti."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/08/pulse-secure-vpns-get-new-urgent-update.html