ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Hackers Exploit Mitel VoIP Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-29499
Unauthenticated RCE in Mitel MiVoice Connect Service Appliance

CVE-2022-29499 is an improper input-validation flaw (CWE-20) in the Service Appliance component (SA 100, SA 400, and Virtual SA) of Mitel MiVoice Connect, affecting releases through 19.2 SP3. A remote, unauthenticated attacker can trigger it by sending improperly validated data to the appliance over the network; the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no privileges, user interaction, or special conditions are required. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, giving the attacker a foothold on the appliance inside the organization's voice/UC environment. Any organization running a MiVoice Connect deployment that includes one of the Service Appliances is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-27 with known ransomware use, and press reports describe the Lorenz ransomware group and others exploiting this Mitel VoIP zero-day for initial access into business networks (EPSS: 55.6% chance of exploitation in 30 days).

Do: Apply Mitel's update for the Service Appliance component per the vendor's instructions, since all releases up through 19.2 SP3 are affected; do not delay, as ransomware groups are actively exploiting the flaw for initial access. Identify whether your MiVoice Connect deployment includes an SA 100, SA 400, or Virtual SA, restrict the appliance's web interface from direct internet exposure until patched, and after updating check the appliance for signs of compromise or follow-on ransomware activity.

9.856% KEV ransomware
  • Mitel MiVoice Connect through 19.2 SP3
  • Mitel MiVoice Connect Service Appliance (SA 100, SA 400, Virtual SA) Service Appliance component in MiVoice Connect through 19.2 SP3
largeestimated tens of thousands of business deployments with thousands of internet-exposed Service Appliances (clearly an estimate)
CVE-2022-29854
A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical

A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

NVD description · AI analysis pending
6.8<1% PoC ×2
  • mitel minet firmware
CVE-2022-29855
Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mitel 6800 Series and 6900 Series SIP phon

Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mitel 6800 Series and 6900 Series SIP phones excluding 6970, versions 5.1 SP8 (5.1.0.8016) and earlier, and 6.0 (6.0.0.368) through 6.1 HF4 (6.1.0.165), could allow a unauthenticated attacker with physical access to the phone to gain root access due to insufficient access control for test functionality during system startup. A successful exploit could allow access to sensitive information and code execution.

NVD description · AI analysis pending
6.8<1% PoC ×2
  • mitel 6873i sip firmware
  • mitel 6930 sip firmware
  • mitel 6940 sip firmware
  • +1 more
Full article477 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJun 24, 2022

A suspected ransomware intrusion attempt against an unnamed target leveraged a Mitel VoIP appliance as an entry point to achieve remote code execution and gain initial access to the environment.

The findings come from cybersecurity firm CrowdStrike, which traced the source of the attack to a Linux-based Mitel VoIP device sitting on the network perimeter, while also identifying a previously unknown exploit as well as a couple of anti-forensic measures adopted by the actor on the device to erase traces of their actions.

The zero-day exploit in question is tracked as CVE-2022-29499 and was fixed by Mitel in April 2022 by means of a remediation script that it shared with customers. It's rated 9.8 out of 10 for severity on the CVSS vulnerability scoring system, making it a critical shortcoming.

"A vulnerability has been identified in the Mitel Service Appliance component of MiVoice Connect (Mitel Service Appliances – SA 100, SA 400, and Virtual SA) which could allow a malicious actor to perform remote code execution (CVE-2022-29499) within the context of the Service Appliance," the company noted in an advisory.

The exploit entailed two HTTP GET requests — which are used to retrieve a specific resource from a server — to trigger remote code execution by fetching rogue commands from the attacker-controlled infrastructure.

In the incident investigated by CrowdStrike, the attacker is said to have used the exploit to create a reverse shell, utilizing it to launch a web shell ("pdf_import.php") on the VoIP appliance and download the open source Chisel proxy tool.

The binary was then executed, but only after renaming it to "memdump" in an attempt to fly under the radar and use the utility as a "reverse proxy to allow the threat actor to pivot further into the environment via the VOIP device." But subsequent detection of the activity halted their progress and prevented them from moving laterally across the network.

The disclosure arrives less than two weeks after German penetration testing firm SySS revealed two flaws in Mitel 6800/6900 desk phones (CVE-2022-29854 and CVE-2022-29855) that, if successfully exploited, could have allowed an attacker to gain root privileges on the devices.

"Timely patching is critical to protect perimeter devices. However, when threat actors exploit an undocumented vulnerability, timely patching becomes irrelevant," CrowdStrike researcher Patrick Bennett said.

"Critical assets should be isolated from perimeter devices to the extent possible. Ideally, if a threat actor compromises a perimeter device, it should not be possible to access critical assets via 'one hop' from the compromised device."

Update: According to security researcher Kevin Beaumont, there are nearly 21,500 publicly accessible Mitel devices online, with the majority located in the U.S., followed by the U.K., Canada, France, and Australia.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/06/hackers-exploit-mitel-voip-zero-day-bug.html