Hackers Exploit VPN to Deploy SUPERNOVA malware on SolarWinds Orion
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-10148 | Authentication Bypass in SolarWinds Orion API (CVE-2020-10148) The SolarWinds Orion API contains a critical authentication bypass (CWE-288/CWE-306, CVSS 9.8) that allows a remote, unauthenticated attacker to execute API commands on the Orion Platform. It is triggered by specially crafted requests to the Orion API that reach endpoints with authorization skipped, requiring no privileges or user interaction. By issuing these API commands, an attacker can take control of the SolarWinds instance; in observed intrusions, the flaw was used to install the SUPERNOVA webshell on Orion servers. Any organization running Orion Platform 2019.4 HF 5, 2020.2 with no hotfix installed, or 2020.2 HF 1 is affected. Exploitation is in the wild: the flaw is listed in CISA's KEV (added 2021-11-03), has been linked to the China-nexus actor DEV-0322 per public reporting, and EPSS assigns it a 92% probability of exploitation within 30 days. Do: Apply the Orion Platform updates/hotfixes per SolarWinds' instructions and move all installations off the affected builds (2019.4 HF 5, 2020.2 without hotfix, 2020.2 HF 1). Until patched, restrict access to the Orion web console and API to trusted networks only. Hunt for compromise by checking for the SUPERNOVA webshell in the Orion web root and reviewing API logs for unauthenticated API command execution. | 9.8 | 92% | KEV |
| largetens of thousands of Orion deployments (roughly 25,000-33,000 customer sites) |
Full article348 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananApr 23, 2021
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has disclosed details of a new advanced persistent threat (APT) that's leveraging the Supernova backdoor to compromise SolarWinds Orion installations after gaining access to the network through a connection to a Pulse Secure VPN device.
"The threat actor connected to the entity's network via a Pulse Secure virtual private network (VPN) appliance, moved laterally to its SolarWinds Orion server, installed malware referred to by security researchers as SUPERNOVA (a .NET web shell), and collected credentials," the agency said on Thursday.
CISA said it identified the threat actor during an incident response engagement at an unnamed organization and found that the attacker had access to the enterprise's network for nearly a year through the use of the VPN credentials between March 2020 and February 2021.
Interestingly, the adversary is said to have used valid accounts that had multi-factor authentication (MFA) enabled, rather than an exploit for a vulnerability, to connect to the VPN, thus allowing them to masquerade as legitimate teleworking employees of the affected entity.
In December 2020, Microsoft disclosed that a second espionage group may have been abusing the IT infrastructure provider's Orion software to drop a persistent backdoor called Supernova on target systems. The intrusions have since been attributed to a China-linked threat actor called Spiral.
Unlike Sunburst and other pieces of malware that have been connected to the SolarWinds compromise, Supernova is a .NET web shell implemented by modifying an "app_web_logoimagehandler.ashx.b6031896.dll" module of the SolarWinds Orion application. The modifications were made possible by leveraging an authentication bypass vulnerability in the Orion API tracked as CVE-2020-10148, in turn permitting a remote attacker to execute unauthenticated API commands.
An investigation into the incident is ongoing. In the meantime, CISA is recommending organizations to implement MFA for privileged accounts, enable firewalls to filter unsolicited connection requests, enforce strong password policies, and secure Remote Desktop Protocol (RDP) and other remote access solutions.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/04/hackers-exploit-vpn-flaw-to-deploy.html