China’s Volt Typhoon reportedly targets US internet providers using Versa zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-39717 | Unrestricted File Upload in Versa Networks Versa Director Exploited by Volt Typhoon CVE-2024-39717 is an unrestricted file upload flaw (CWE-434) in the interface customization function of Versa Networks' Versa Director: the 'Change Favicon' option in the GUI accepts an uploaded file that merely ends in a .png extension, so a malicious file can masquerade as an image. Exploitation requires network access to the Director GUI and valid credentials for a Provider-Data-Center-Admin or Provider-Data-Center-System-Admin account (tenant-level users cannot reach the feature), which is why the 7.2 CVSS score includes 'high privileges required.' By planting a dangerous file disguised as a .png, an attacker gains a code-execution path on the Director server consistent with the flaw's high confidentiality, integrity and availability impact ratings. Any organization running Versa Director — particularly service providers and internet providers whose management interface is reachable from the internet — is potentially affected. Exploitation is confirmed in the wild: China-linked actor Volt Typhoon used the flaw as a zero-day against U.S. and global IT targets, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-23, and federal agencies were urged to patch by September 2024. Do: Apply Versa Networks' fix/mitigation instructions — CISA's required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable — and meet the September 2024 federal remediation deadline if applicable. Restrict access to the Versa Director GUI to trusted management networks rather than exposing it to the internet, and audit and rotate credentials for Provider-Data-Center-Admin and Provider-Data-Center-System-Admin accounts, since the observed Volt Typhoon activity relied on valid high-privilege logins. Check Director systems for unexpected files uploaded through the Change Favicon feature that may be disguised as .png images. | 7.2 | 4% | KEV |
| moderate≈ low thousands of Versa Director deployments worldwide, of which only a small fraction are internet-exposed |
Full article648 words · extracted from therecord.media · click to collapse
Researchers accused Chinese government-linked hacking group Volt Typhoon of exploiting a zero-day vulnerability in network management platform Versa Director in an effort to breach internet service providers and technology companies, including those in the United States. Earlier on Monday, Versa announced that it had fixed a high-severity flaw, tracked as CVE-2024-39717, noting that it was exploited in the wild by an unnamed nation-state hacker group “at least once.” The bug also had been added to the Cybersecurity and Infrastructure Security Agency (CISA) known exploited vulnerability catalog over the weekend. This flaw affects all Versa Director versions prior to 22.1.4. Versa Director works as a central command center, allowing tech specialists to easily set up, monitor, and manage their networks across multiple locations. This makes Versa servers an “attractive target for threat actors seeking to extend their reach within enterprise network management,” according to researchers at Lumen Technologies. In a report on Tuesday, the researchers attributed the exploitation of this vulnerability, “with moderate confidence,” to the notorious China-backed hacker group Volt Typhoon. The group has previously targeted U.S. energy and defense companies, with its hallmark campaign involving the infiltration of home routers to launch other attacks. In the latest incidents, Volt Typhoon exploited the flaw in Versa Director to upload a sophisticated, custom-tailored web shell named VersaMem. This web shell was used to intercept and harvest credentials, as well as execute arbitrary malicious code on compromised servers while avoiding detection. The targets of Volt Typhoon’s latest campaign reportedly include four U.S. victims and one non-U.S. victim in the internet service provider, managed service provider, and information technology sectors. The initial version of the VersaMem web shell was first uploaded to the VirusTotal repository from Singapore earlier in June, approximately five days prior to the earliest identified exploitation of Versa Director servers in the U.S., Lumen Technologies said. “We suspect the threat actors may have been testing the web shell in the wild on non-U.S. victims before deploying it to U.S. targets,” the company added. The current malware version has zero detections on VirusTotal. “Given the severity of the vulnerability, the sophistication of the threat actors, the critical role of Versa Director servers in the network, and the potential consequences of a successful compromise, researchers consider this exploitation campaign to be highly significant,” the researchers added. Lumen Technologies said it shared its findings with U.S. federal agencies to warn “of the emerging risks that could impact our nation’s strategic assets.” For the last year, the White House, Defense Department and several other agencies with a hand in cybersecurity have raised alarms about the Volt Typhoon campaign, which they believe is a preemptive effort by China’s government to gain strategic footholds into U.S. critical infrastructure. The goal is to slow down any potential military mobilization effort that may come following a Chinese invasion of Taiwan, according to government officials. U.S. officials continue to search for and root out compromises caused by Volt Typhoon. CISA Director Jen Easterly said earlier this month that escalating tensions between China and Taiwan have led Beijing to seek ways to launch destructive attacks against the island nation and its allies — including the U.S. “[This is] a world where a war in Asia will be accompanied by very serious threats for Americans,” she said. “The explosion of pipelines, the pollution of water systems, the derailing of our transportation systems, the severing of our communications, specifically to incite panic and societal chaos and to deter our ability to marshal military might and citizen will.”
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/versa-zero-day-volt-typhoon-china