
Organizations around the world are putting their security We are again aware of the risks of not installing updates.
Both vulnerabilities have severity ratings of 9.8 out of 10 possible and exist in two unrelated products that are important in securing large networks. The first, tracked as CVE-2022-47966, is a pre-authentication remote code execution vulnerability that exists in 24 products from software maker Zoho using Zoho’s ManageEngine. It was patched in October/November of last year. The second vulnerability, CVE-2022-39952, affects a product called FortiNAC, made by cybersecurity firm Fortinet, and was patched last week.
Both ManageEngine and FortiNAC are billed as Zero Trust products. In other words, it works under the assumption that your network has been compromised and constantly monitors that your devices are not infected or acting maliciously. Zero Trust products do not trust network devices or nodes on the network and actively validate that they are secure.
24 Zoho products affected
ManageEngine is the motor that powers Zoho’s wide range of network management software and appliances that perform core functions. For example, AD Manager Plus helps an administrator set up and maintain her Active Directory, a Windows service for creating and deleting all user accounts on the network and delegating system privileges to each account. . Password Manager Pro provides a centralized digital vault for storing all password data for your network. Other products enabled by ManageEngine manage desktops, mobile devices, servers, applications and service desks.
CVE-2022-47966 allows attackers to remotely execute malicious code by issuing standard HTTP POST requests with specially crafted responses using the Security Assertion Markup Language . The vulnerability is due to Zoho using an older version of Apache Santuario to validate his XML signatures.
In January, nearly two months after Zoho patched the ManageEngine vulnerability, security firm Horizon3.ai released a detailed analysis that included proof-of-concept exploit code. Within a day, security firms such as Bitdefender began seeing clusters of active attacks by multiple threat actors targeting organizations around the world that had not yet installed security updates.
Some attacks have exploited this vulnerability to install tools such as command line Netcat, from which the Anydesk remote login software was installed. If successful, the attacker sells initial access to other threat groups. Other threat actors have exploited this vulnerability to install ransomware known as Buhti, post-exploitation tools such as Cobalt Strike and RAT-el, and malware used for espionage.
“This vulnerability is a stark reminder of the importance of keeping systems up-to-date with the latest security patches while employing strong perimeter defenses,” Bitdefender researchers wrote. “Attackers don’t need to hunt around for new exploits and new techniques when they know that many organizations are vulnerable to old exploits due to lack of proper patch management and risk management. “
A Zoho representative did not respond to an email requesting comment on this post.
FortiNAC Under “Massive” Attack
CVE-2022-39952, on the other hand, resides in FortiNAC, a network access control solution that identifies and monitors all devices connected to a network. Large organizations use FortiNAC to protect operational technology networks of industrial control systems, IT appliances, and Internet of Things devices. A class of vulnerabilities known as external control of filenames or paths allows unauthenticated attackers to write arbitrary files to the system from which they can obtain remote code execution executed with unfettered root privileges.
Fortinet patched the vulnerability on February 16, and within days, researchers at multiple organizations reported that the vulnerability was being actively exploited. The alerts were from organizations or companies including: shadow server, Cronup, and gray noise. Once again, Horizon3.ai provided an in-depth study analyzing what caused the vulnerability and how it could be weaponized.
A Cronup researcher wrote:
This vulnerability has been exploited by multiple seeming attackers attempting to install various web shells that provide a text window from which the attacker can issue commands remotely.
Fortinet CTO Carl Windsor said in a blog post published Thursday that the company regularly conducts internal security audits to uncover security bugs in its products.
“Importantly, it was during one of these internal audits that the Fortinet PSIRT team themselves identified this remote code execution vulnerability,” Windsor wrote. “We immediately revised this finding and published it as part of our February PSIRT advisory (if you have not registered for the advisory, please use one of the methods described here). Registration is highly recommended.) Fortinet’s PSIRT policy balances a culture of transparency with a commitment to the safety of our customers.”
Several Fortinet products have been actively abused in recent years. In 2021, his three vulnerabilities in Fortinet’s FortiOS VPN (two in 2019 and one in a year) will target attackers trying to access multiple government, commercial and technology services. became. Last December, an unknown attacker exploited another critical vulnerability in FortiOS SSL-VPN to infect governments and government-affiliated organizations with his highly custom malware. Fortinet quietly patched the vulnerability in late November, but did not disclose it until the actual attack began. The company has yet to explain its reasons or policy for disclosing the vulnerabilities in its products.
Recent attacks have shown that security products designed to keep attackers away from protected networks can be a double-edged sword, if companies don’t disclose them or, more recently, if customers It can be especially dangerous if you don’t install updates.Those who manage or oversee networks that use either ManageEngine or FortiNAC should immediately check for vulnerabilities. The research post linked above provides a wealth of indicators that can be used to determine if people are being targeted.