Unpatched Vulnerabilities Expose Yifan Industrial Routers to Attacks

Industrial routers made by Chinese company Yifan are affected by several critical vulnerabilities that can expose organizations to attacks, Cisco’s Talos threat intelligence and research group reported on Wednesday.

The vendor was notified in late June and given more than 90 days to release patches. However, no fixes appear to have been released and Cisco has made public the technical details in accordance with its vulnerability disclosure policy. 

A Talos researcher discovered over a dozen vulnerabilities in Yifan’s YF325 cellular router. According to the vendor, the device has been deployed in various fields, including self-service terminals, intelligent transportation, industrial automation, smart grid, water supply, finance, and point-of-sale systems. 

A majority of the flaws found in the router have been assigned ‘critical severity’ ratings and the remaining have been classified as ‘high severity’. 

Talos said the most serious of the security holes can be exploited to execute an arbitrary shell on the targeted router (CVE-2023-32632), change the admin credentials of the device and obtain root access (CVE-2023-24479), and leverage leftover debug credentials to access the device with admin privileges (CVE-2023-32645).

The remaining weaknesses can be exploited for arbitrary code/command execution and denial-of-service (DoS) attacks.

All vulnerabilities can be exploited by sending specially crafted network requests to the targeted device.

SecurityWeek has reached out to Yifan for comment and will update this article if the company responds. 

Advertisement. Scroll to continue reading.

Related: Dozens of RCE Vulnerabilities Impact Milesight Industrial Router

Related: InHand Industrial Router Vulnerabilities Expose Internal OT Networks to Attacks

Related: 10 Vulnerabilities Found in Widely Used Robustel Industrial Routers

https://www.securityweek.com/unpatched-vulnerabilities-expose-yifan-industrial-routers-to-attacks/




Critical SOCKS5 Vulnerability in cURL Puts Enterprise Systems at Risk

The maintainers of the cURL data transfer project on Wednesday rolled out patches for a severe memory corruption vulnerability that exposes millions of enterprise OSes, applications and devices to malicious hacker attacks.

According to an high-risk bulletin, the flaw poses a direct threat to the SOCKS5 proxy handshake process in cURL and can be exploited remotely in some non-standard configurations.

The bug, tracked as CVE-2023-38545, exists in the libcurl library that handles data exchange between devices and servers.

From the advisory:

“When curl is asked to pass along the hostname to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that hostname can be is 255 bytes.

If the hostname is detected to be longer than 255 bytes, curl switches to local name resolving and instead passes on the resolved address only to the proxy. Due to a bug, the local variable that means “let the host resolve the name” could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long hostname to the target buffer instead of copying just the resolved address there.”

Swedish open source developer and curl maintainer Daniel Stenberg explained that the bug was introduced in February 2020 during related coding work on cURL’s SOCKS5 support.

Advertisement. Scroll to continue reading.

“An attacker that controls an HTTPS server that a libcurl using client accesses over a SOCKS5 proxy (using the proxy-resolver-mode) can make it return a crafted redirect to the application via a HTTP 30x response,” Stenberg explained, warning that in certain conditions, a heap buffer overflow is triggered.

“This problem is the worst security problem found in [libcurl] in a long time,” Stenberg said. The issue was reported via the HackerOne platform by Jay Satiro and paid out $4,600, the largest cURL bug bounty to date.

Affected versions have been flagged as libcurl versions 7.69.0 to 8.3.0.  The project said the issue has been fixed in cURL 8.4.0.

cURL provides both a library (libcurl) and command-line tool (curl) for transferring data with URL syntax, supporting various network protocols, including SSL, TLS, HTTP, FTP, SMTP, among others.

Earlier this week, cURL released a pre-patch advisory urging organizations to urgently inventory and scan all systems utilizing curl and libcurl and prepare to apply the patches in cURL 8.4.0.

According to curl’s maintainers, the vulnerability potentially impacts all projects relying on libcurl, although some software may use it in a way that does not allow exploitation. “Updating the shared libcurl library should be enough to fix this issue on all operating systems.”

Related: Patches Prepared for ‘Probably Worst’ cURL Vulnerability

Related: Newly Exploited Zero-Days in WordPad, Skype for Business

Related: Information Disclosure, DoS Flaws Patched in libcurl

Related: cURL Security Audit Reveals Several Vulnerabilities

https://www.securityweek.com/critical-socks5-vulnerability-in-curl-puts-enterprise-systems-at-risk/




Citrix Patches Critical NetScaler ADC, Gateway Vulnerability

Citrix on Tuesday announced patches for a critical-several vulnerability impacting multiple versions of NetScaler Application Delivery Controller (ADC) and NetScaler Gateway.

Tracked as CVE-2023-4966 (CVSS score of 9.4), the security defect could lead to sensitive information disclosure, the tech giant notes in an advisory.

According to Citrix, the issue can be exploited without authentication on appliances that are configured as a Gateway or an AAA virtual server.

The flaw affects NetScaler ADC and NetScaler Gateway versions 14.1, 13.1, 13.0, and NetScaler ADC 13.1-FIPS, 12.1-FIPS, and 12.1-NDcPP.

Citrix has released NetScaler ADC and NetScaler Gateway versions 14.1-8.50, 13.1-49.15, 13.0-92.19, and NetScaler ADC 13.1-FIPS 13.1-37.164, 12.1-FIPS 12.1-55.300, and 12.1-NDcPP 12.1-55.300 to address the vulnerability.

“NetScaler ADC and NetScaler Gateway version 12.1 is now End-of-Life (EOL) and is vulnerable. Customers are recommended to upgrade their appliances to one of the supported versions that address the vulnerabilities,” Citrix says.

The company also notes that only customer-managed NetScaler ADC and Gateway products are impacted and should be updated to a patched release.

Advertisement. Scroll to continue reading.

The updates also address a high-severity denial-of-service (DoS) flaw – CVE-2023-4967, CVSS score of 8.2 – impacting products configured as gateways or AAA virtual servers.

On Tuesday, Citrix also announced hotfixes for five vulnerabilities in Citrix Hypervisor 8.2 CU1 LTSR that could allow malicious code running in a guest VM to compromise the host, crash the host, crash another VM running on the host, or access information from code running on the same CPU core.

Four of these issues (CVE-2023-20588, CVE-2023-34324, CVE-2023-34326, and CVE-2023-3432) only impact systems running on AMD CPUs, while the fifth (CVE-2022-1304) can only be exploited when a host administrator uses a restore sub-option in the on-host xsconsole interface.

“Note that there is not a one-to-one correlation between these hotfixes and the addressed issues; we recommend that you always apply all of the hotfixes,” the tech giant’s advisory reads.

Citrix makes no mention of any of these vulnerabilities being exploited in the wild, but threat actors are known to have targeted publicly disclosed NetScaler ADC and Gateway vulnerabilities in malicious attacks.

The US cybersecurity agency CISA warns that attackers could exploit one of these vulnerabilities to take control of affected systems and encourages administrators to review Citrix’s advisories and apply the necessary patches.

Related: Credential Harvesting Campaign Targets Unpatched NetScaler Instances

Related: Exploitation of Citrix ShareFile Vulnerability Spikes as CISA Issues Warning

Related: Citrix Patches High-Severity Vulnerabilities in Windows, Linux Apps

https://www.securityweek.com/citrix-patches-critical-netscaler-adc-gateway-vulnerability/




Chrome 118 Patches 20 Vulnerabilities

Google on Tuesday announced the release of Chrome 118 to the stable channel with fixes for 20 vulnerabilities, including 14 reported by external researchers.

The most severe of the externally reported flaws is CVE-2023-5218, a critical bug described as a use-after-free issue in Site Isolation, Chrome’s component responsible for preventing sites from stealing other sites’ data.

Implemented in Chrome as an additional security measure on top of the code that enforces the Same Origin Policy, Site Isolation groups pages from different domains in different processes that run in their own sandboxes.

While Google does not provide details on CVE-2023-5218, use-after-free bugs in Site Isolation can typically allow attackers to perform a sandbox escape via a crafted HTML page, which could potentially allow them to execute arbitrary code.

The internet giant notes in its advisory that it has yet to determine the bug bounty reward for this vulnerability.

Chrome 118 also resolves eight medium-severity flaws reported by external researchers, six of which are inappropriate implementation issues in Fullscreen, Navigation, DevTools, Intents, Downloads, and Extensions API.

A use-after-free vulnerability in Blink History and a heap buffer overflow bug in PDF, both medium-severity flaws, were also resolved.

Advertisement. Scroll to continue reading.

The remaining five externally reported issues patched in this browser release are low-severity vulnerabilities: four inappropriate implementations and a use-after-free.

Google says it has handed out over $30,000 in bug bounty rewards to the reporting researchers. However, the final amount might be much higher, once the reward for the critical-severity vulnerability is determined.

The internet giant makes no mention of any of these vulnerabilities being exploited in malicious attacks.

The latest Chrome release is now rolling out as version 118.0.5993.70 for macOS and Linux, and as versions 118.0.5993.70/.71 for Windows.

Related: Google Patches Chrome Zero-Day Reported by Apple, Spyware Hunters

Related: Password-Stealing Chrome Extension Demonstrates New Vulnerabilities

Related: Chrome 116 Update Patches High-Severity Vulnerabilities

https://www.securityweek.com/chrome-118-patches-20-vulnerabilities/




Organizations Respond to HTTP/2 Zero-Day Exploited for DDoS Attacks

Major tech companies and other organizations have rushed to respond to the newly disclosed HTTP/2 zero-day vulnerability that has been exploited to launch the largest distributed denial-of-service (DDoS) attacks seen to date.

The existence of the attack method, named HTTP/2 Rapid Reset, and the underlying vulnerability, tracked as CVE-2023-44487, were disclosed on Tuesday by Cloudflare, AWS and Google.

Each of the tech giants saw DDoS attacks aimed at customers peaking at hundreds of millions of requests per second, far more than they had previously seen. One noteworthy aspect is that the attacks came from relatively small botnets powered by just tens of thousands of devices. 

While their existing DDoS protections were largely able to block the attacks, Google, Cloudflare and AWS implemented additional mitigations for this specific attack vector. In addition, they notified web server software companies, which have started working on patches.

The new attack method abuses an HTTP/2 feature called ‘stream cancellation’. Attackers repeatedly send a request and immediately cancel it, which results in a DoS condition capable of taking down servers and applications running standard HTTP/2 implementations. 

Several organizations have published blog posts, advisories and alerts on Tuesday in response to the HTTP/2 Rapid Reset vulnerability.

CISA

Advertisement. Scroll to continue reading.

The US cybersecurity agency CISA has released an alert to warn organizations about the threat posed by HTTP/2 Rapid Reset, providing links to various useful resources, including its own guidance for mitigating DDoS attacks.

Microsoft

Microsoft published an advisory to inform customers that it’s aware of the HTTP/2 Rapid Reset attack. The tech giant has advised users to install the available web server updates and provided a couple of workarounds that involve disabling the HTTP/2 protocol using the Registry Editor, and limiting applications to HTTP1.1 using protocol settings for each Kestral endpoint. 

NGINX

NGINX warned that the HTTP/2 Rapid Reset vulnerability can — under certain conditions — be exploited to launch a DoS attack on NGINX Open Source, NGINX Plus, and related products that implement the server-side portion of the HTTP/2 specification. Users have been advised to immediately update their NGINX configuration.

OpenSSF

The Open Source Security Foundation (OpenSSF) has published a blog post calling attention to the underlying vulnerability, pointing out that the issue highlights the need for rapid response. 

F5

F5 said the vulnerability allows a remote, unauthenticated attacker to cause an increase in CPU usage that can lead to a DoS condition on BIG-IP systems. The company’s advisory contains a list of affected products and mitigations. 

Netty

Developers of Netty, a framework designed for the development of network applications such as protocol servers and clients, announced the release of version 4.1.100.Final, which fixes the HTTP/2 DDoS attack vector.

Apache

Apache Tomcat developers have confirmed that Tomcat’s HTTP/2 implementation is vulnerable to the Rapid Reset attack. Apache Tomcat 10.1.14 fixes CVE-2023-44487.

Swift

Swift, the programming language for Apple applications, has informed users that if they run a publicly accessible HTTP/2 server using ‘swift-nio-http2’ they should immediately update to version 1.28.0.

Linux distributions

Linux distributions such as Red Hat, Ubuntu and Debian have also published advisories for CVE-2023-44487. 

Related: CISA Releases Guidance on Adopting DDoS Mitigations

Related: Canadian Government Targeted With DDoS Attacks by Pro-Russia Group

Related: After Microsoft and X, Hackers Launch DDoS Attack on Telegram

https://www.securityweek.com/organizations-respond-to-http-2-zero-day-exploited-for-ddos-attacks/




CISA Warns of Attacks Exploiting Adobe Acrobat Vulnerability 

The US cybersecurity agency CISA on Tuesday announced that it has added five more security defects to its Known Exploited Vulnerabilities catalog, warning organizations of attacks exploiting an Adobe Acrobat and Reader flaw that came to light earlier this year.

The Adobe Acrobat and Reader issue is CVE-2023-21608, a use-after-free vulnerability which can be exploited to achieve remote code execution (RCE) with the privileges of the current user.

Adobe released patches for this flaw in January 2023, but numerous proof-of-concept (PoC) exploits and technical write-ups have been published since, creating opportunities for threat actors to start targeting the issue in attacks.

Although there appear to be no public reports describing in-the-wild exploitation of CVE-2023-21608, CISA says it only adds CVEs to the KEV list based on solid proof that exploitation has occurred.

CISA also expanded KEV with CVE-2023-20109, an out-of-bounds write flaw in the Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS and IOS XE.

Also leading to RCE, the bug was patched at the end of September, when Cisco warned that it had observed exploitation attempts targeting it.

On the same day that Microsoft released patches for two zero-days impacting Skype for Business (CVE-2023-41763) and WordPad (CVE-2023-36563), CISA added both flaws to KEV. Neither Microsoft nor CISA have provided details on the observed attacks.

Advertisement. Scroll to continue reading.

The fifth vulnerability that CISA has added to KEV on Tuesday is a zero-day in the HTTP/2 protocol, which has been exploited in some of the largest distributed denial-of-service (DDoS) attacks to date.

Referred to as HTTP/2 Rapid Reset, the attack method involves repeatedly sending requests and immediately canceling them. All applications and servers running the standard implementation of HTTP/2 are vulnerable to this attack.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA’s warning reads.

As per the Binding Operational Directive (BOD) 22-01, federal agencies have 21 days to identify the vulnerable products within their networks and apply the available patches and mitigations.

CISA’s BOD 22-01 only applies to federal agencies, but CISA encourages all organizations to review the KEV catalog and prioritize remediation of the security defects in it, or discontinue the use of the vulnerable products if mitigations are not available.

Related: Faster Patching Pace Validates CISA’s KEV Catalog Initiative

Related: Organizations Warned of Top 10 Cybersecurity Misconfigurations Seen by CISA, NSA

Related: CISA Reverses Course on Malicious Exploitation of Video Conferencing Device Flaws

https://www.securityweek.com/cisa-warns-of-attacks-exploiting-adobe-acrobat-vulnerability/




Microsoft Blames Nation-State Threat Actor for Confluence Zero-Day Attacks

Researchers at Microsoft say a known nation-state threat actor is behind the zero-day exploits hitting Atlassian’s Confluence Data Center and Server products.

A note from Redmond linked the ongoing attacks to an APT group tracked as Storm-0062 and warned that malicious activity dates back to September 14, a full three weeks before Atlassian’s public disclosure of the issue.

“Microsoft has observed nation-state threat actor Storm-0062 exploiting CVE-2023-22515 in the wild since September 14, 2023. CVE-2023-22515 was disclosed on October 4, 2023. Storm-0062 is tracked by others as DarkShadow or Oro0lxy,” the company said.

According to SecurityWeek sources, the Storm-0062 hacking team has been observed conducting cyberespionage operations for  China’s Ministry of State Security, a state intelligence agency.

Microsoft shared four IP addresses that were seen sending related exploit traffic targeting the critical CVE-2023-22515 privilege escalation vulnerability. 

“Any device with a network connection to a vulnerable application can exploit CVE-2023-22515 to create a Confluence administrator account within the application,” Microsoft said, confirming earlier warnings from Atlassian that patches should be applied with urgency.

“Organizations with vulnerable Confluence applications should upgrade as soon as possible to a fixed version: 8.3.3, 8.4.3, or 8.5.2 or later. Organizations should isolate vulnerable Confluence applications from the public internet until they are able to upgrade them,” the company added.

Advertisement. Scroll to continue reading.

Atlassian updated its own advisory to confirm it has evidence that a known nation-state actor is actively exploiting the bug.

On October 4, Atlassian rushed out an urgent patch for the issue alongside a notice that “a handful of customers” were hit by remote exploits.

“Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts and access Confluence instances,” the Australian company said.

The vulnerability, tracked as CVE-2023-22515, is described as a remotely exploitable privilege escalation issue affecting on-prem instances of Confluence Server and Confluence Data Center.

“Instances on the public internet are particularly at risk, as this vulnerability is exploitable anonymously,” Atlassian warned. “If an instance has already been compromised, upgrading will not remove the compromise.”

Atlassian published an FAQ urging business users to immediately check all affected Confluence instances for the following indicators of compromise:

  • Unexpected members of the confluence-administrator group
  • Unexpected newly created user accounts
  • Requests to /setup/*.action in network access logs
  • Presence of /setup/setupadministrator.action in an exception message in atlassian-confluence-security.log in the Confluence home directory

“If it is determined that your instance has been compromised, our advice is to immediately shut down and disconnect the server from the network/Internet. Also, you may want to immediately shut down any other systems which potentially share a user base or have common username/password combinations with the compromised system,” Atlassian added.

Security problems in Atlassian’s software products have been targeted in the past by both cybercriminal and state-sponsored threat actors. In CISA’s KEV (Known Exploited Vulnerabilities) catalog, there are six distinct Confluence vulnerabilities marked for urgent attention.

Related: Atlassian Ships Urgent Patch for Exploited Confluence Zero-Day

Related: Atlassian Patches Critical Bitbucket Security Defect

Related: Expects Confluence App Exploitation After Password Leak

Related: Atlassian Patches Remote Vulnerabilities in Confluence, Bamboo

Related: Cybercriminals, State-Sponsored APTs Exploiting Confluence Flaw

https://www.securityweek.com/microsoft-blames-nation-state-threat-actor-for-confluence-zero-day-attacks/




Patch Tuesday: Code Execution Flaws in Adobe Commerce, Photoshop

Software maker Adobe on Tuesday released fixes for at least 13 security vulnerabilities in multiple product lines, warning that critical flaws in Adobe Commerce and Photoshop will require immediate attention.

As part of its scheduled batch of Patch Tuesday updates, Adobe documented at least 10 serious flaws in Adobe Commerce and Magento Open Source, a product line often targeted by malicious hackers.

“Successful exploitation could lead to arbitrary code execution, privilege escalation, arbitrary file system read, security feature bypass and application denial-of-service,” Adobe said in a critical-severity advisory.

The company identified the affected software versions as Adobe Commerce (multiple versions including 2.4.7-beta1 and earlier) and Magento Open Source (Multiple versions including 2.4.7-beta1 and earlier.)

Adobe said it was not aware of exploits for any of the documented vulnerabilities.

The San Jose, Calif. firm also released updates to fix a critical-severity flaw in the popular Adobe Photoshop software.  The flaw, tagged as CVE-2023-26370, could be exploited to launch code execution attacks on both Windows and macOS systems.

Adobe said the patches apply to Photoshop 2022 (23.5.5 and earlier versions) and Photoshop 2023 (24.7 and earlier versions). 

Advertisement. Scroll to continue reading.

Adobe’s security response team also released fixes for a pair of vulnerabilities in Adobe Bridge that could lead to memory corruption exploitation.

Related: Adobe Says Critical PDF Reader Zero-Day Being Exploited 

Related: Critical Flaws in Adobe Commerce Software

Related: Patch for Exploited Flaw in Adobe Commerce and Magento Bypassed

Related: Adobe Plugs Critical Security Holes in Illustrator, After Effects Software

https://www.securityweek.com/patch-tuesday-code-execution-flaws-in-adobe-commerce-photoshop/




SAP Releases 7 New Notes on October 2023 Patch Day

German software maker SAP this week announced the release of seven new and two updated security notes as part of its October 2023 Security Patch Day.

The most severe of the security notes brings an update to the Chromium browser in SAP Business Client, which contains 37 fixes, including two critical- and 20 high-severity vulnerabilities.

One of these critical flaws, enterprise application security firm Onapsis notes, is CVE-2023-4863 an already exploited bug in the libwebp image rendering library, which vendors have been scrambling to patch lately.

Since libwebp is used in multiple applications other than web browsers, organizations are advised to check all their software for the presence of this vulnerability and apply available patches accordingly.

The update also addresses CVE-2023-5217, another exploited vulnerability that Google rolled out patches for in September and which CISA added to its Known Exploited Vulnerabilities catalog recently.

The second updated security note that SAP released this week addresses a log injection flaw in NetWeaver. Tracked as CVE-2023-31405 (CVSS score of 5.3), the vulnerability was initially patched in July 2023.

“Unlike many other updates, the updated note does not completely replace the initial patch. Customers need to implement both notes to be fully protected. While the initial note contains patches for all three affected software components (ENGINEAPI, SERVERCORE, and J2EE-APPS), [the update] only updates the ENGINEAPI component since the patch for this component was incomplete,” Onapsis explains.

Advertisement. Scroll to continue reading.

The remaining seven security notes described in SAP’s latest advisory deal with medium-severity bugs only, making this one of “the calmest Patch Days of the last 5 years,” as Onapsis points out.

The notes address issues such as cross-site scripting (XSS), missing XML validation, server-side request forgery (SSRF), missing authorization check, log injection, and information disclosure bugs impacting BusinessObjects, PowerDesigner Client, NetWeaver, S/4HANA, Business One, and Statutory Reporting.

Related: SAP Patches Critical Vulnerability Impacting NetWeaver, S/4HANA

Reated: SAP Patches Critical Vulnerability in PowerDesigner Product

Reated: SAP Patches Critical Vulnerability in ECC and S/4HANA Products

https://www.securityweek.com/sap-releases-7-new-notes-on-october-2023-patch-day/




One-Click GNOME Exploit Could Pose Serious Threat to Linux Systems

GitHub’s Security Lab has warned Linux users about a serious remote code execution vulnerability affecting a component of the popular GNOME desktop environment.

The flaw was found in Libcue, a library designed for parsing ‘cue’ files, which describe how the tracks on a CD are laid out. Libcue is used by a search engine called Tracker Miners, which in turn is used by GNOME to index files in the home directory to make searches more efficient. 

GitHub Security Lab researcher Kevin Backhouse discovered that Libcue is affected by a vulnerability — tracked as CVE-2023-43641 — that can be exploited for remote code execution by getting the targeted user to click on a malicious link. 

Backhouse has made available a video showing how an attacker could exploit the vulnerability to launch the calculator on a Linux system by getting the targeted user to click on a link that triggers a cue file download. When the attacker’s file is saved on the victim’s device, it’s automatically scanned by Tracker Miners and processed using the Libcue library, which triggers the exploit and executes the attacker’s code.

Backhouse has made public technical details, but said the weaponized proof-of-concept (PoC) exploit for CVE-2023-43641 will not be released until users have had the chance to install the patch. 

The exploit has been tested against Ubuntu and Fedora, but the researcher believes all distributions running GNOME could be vulnerable. However, he noted that the exploit requires some tweaking for each distribution. 

A simple version of the PoC, which causes a benign crash, has been made public to allow users to check whether their system is vulnerable to attacks exploiting CVE-2023-43641.

Advertisement. Scroll to continue reading.

“Sometimes a vulnerability in a seemingly innocuous library can have a large impact. Due to the way that it’s used by tracker-miners, this vulnerability in libcue became a 1-click RCE. If you use GNOME, please update today!” Backhouse said.

Related: Severe Glibc Privilege Escalation Vulnerability Impacts Major Linux Distributions

Related: StackRot Linux Kernel Vulnerability Shows Exploitability of UAFBR Bugs

Related: In Other News: Hacking Encrypted Linux Computers, Android Fuzzing, Skype Leaking IPs

https://www.securityweek.com/one-click-gnome-exploit-could-pose-serious-threat-to-linux-systems/