Exploitation of 5-Year-Old TBK DVR Vulnerability Spikes

Fortinet warns of a massive spike in exploitation attempts targeting a five-year-old authentication bypass vulnerability in TBK DVR devices.

A video surveillance company, TBK Vision provides network CCTV devices, DVRs, and other types of related equipment for protecting industrial and critical infrastructure facilities.

The vendor claims it has over 600,000 cameras, 50,000 CCTV recorders, and other devices being used by organizations in banking, government, retail, and other sectors.

Tracked as CVE-2018-9995 (CVSS score of 9.8), the issue can be exploited remotely by sending a crafted HTTP cookie, providing the attacker with administrative access to a vulnerable device. The attacker could then access camera video feeds.

Details on this critical-severity bug were published in April 2018, when security researcher Fernandez Ezequiel also published proof-of-concept (PoC) code exploiting it. To date, however, the vendor has not provided a patch to address the bug.

The issue impacts TBK’s DVR4104 and DVR4216 devices, which are also rebranded and sold under the CeNova, DVR Login, HVR Login, MDVR Login, Night OWL, Novo, QSee, Pulnix, Securus, and XVR 5 in 1 brands, a NIST advisory reads.

According to Fortinet, during April 2023 alone, its intrusion prevention systems (IPSs) detected more than 50,000 exploitation attempts targeting CVE-2018-9995.

“With tens of thousands of TBK DVRs available under different brands, publicly-available PoC code, and an easy-to-exploit makes this vulnerability an easy target for attackers. The recent spike in IPS detections shows that network camera devices remain a popular target for attackers,” Fortinet notes.

Organizations are advised to review the CCTV cameras, DVRs, and related equipment they are using and remove any vulnerable models from their environments or ensure that they are protected by a firewall and not directly accessible from the internet.

Fortinet also observed an increase in exploitation attempts targeting a seven-year-old vulnerability in MVPower CCTV DVR models.

Tracked as CVE-2016-20016 (CVSS score of 9.8) and referred to as ‘JAWS webserver RCE’, the flaw allows an unauthenticated remote attacker to execute arbitrary system commands with root privileges.

Previously, CVE-2016-20016 was seen exploited in attacks between 2017 and 2022.

Related:New BotenaGo Variant Infects Lilin Security Cameras With Mirai

Related: CISA Adds 66 Vulnerabilities to ‘Must Patch’ List

Related:Necro Python Botnet Starts Targeting Visual Tools DVRs

Exploitation of 5-Year-Old TBK DVR Vulnerability Spikes




Cisco Working on Patch for Vulnerability Reported by NATO Pentester

Cisco informed customers this week that it’s working on a patch for a vulnerability found in the company’s Prime Collaboration Deployment product by a member of NATO’s Cyber Security Centre (NCSC).

Prime Collaboration Deployment is a tool designed to assist in the management of Unified Communications (UC) applications.

The security hole, identified as CVE-2023-20060, is a cross-site scripting (XSS) issue affecting the product’s web-based management interface. 

“An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information,” Cisco explained in its advisory.

Cisco said there was no evidence of exploitation in the wild, but vulnerabilities found in the company’s products have been known to be targeted in attacks.

The company has not said when it expects a patch to become available and there are no workarounds to address the vulnerability. 

The networking giant has credited Pierre Vivegnis, who works as a penetration tester and security researcher at NATO, for reporting the vulnerability.

It has become increasingly common for government agencies to responsibly disclose the vulnerabilities they find to vendors. The NSA has reported multiple vulnerabilities to Cisco in the past year, and the UK’s National Cyber Security Centre (NCSC) was recently credited for finding flaws in industrial products. 

Of course, governments are also known to stockpile vulnerabilities and exploits for use in their cyber operations. 

Related: Cisco Patches High-Severity Vulnerabilities in IOS Software

Related: Cisco Patches Code and Command Execution Vulnerabilities in Several Products

Related: Cisco Patches Critical Vulnerabilities in Industrial Network Director, Modeling Labs

https://www.securityweek.com/cisco-working-on-patch-for-vulnerability-reported-by-nato-pentester/




FDA, CISA: Illumina Medical Devices Vulnerable to Remote Hacking

The US government is notifying healthcare providers and lab personnel about a component used by several Illumina medical devices being affected by serious vulnerabilities that can allow remote hacking.

On Thursday, the Cybersecurity and Infrastructure Security Agency (CISA) and the Food and Drug Administration (FDA) issued public notifications to inform organizations about the vulnerabilities affecting the Universal Copy Service (UCS) component used by several of Illumina’s genetic sequencing instruments. 

The vendor has released patches and mitigations, and published its own advisory to inform customers about the steps they have to take to prevent potential exploitation. 

The FDA said it was not aware of any attacks exploiting the vulnerabilities in the wild, but warned that a hacker could exploit them to remotely take control of a device, or to alter configurations, settings, software or data on the device or the user’s network. 

The FDA also warned that exploitation of the vulnerabilities could also impact “genomic data results in the instruments intended for clinical diagnosis, including causing the instruments to provide no results, incorrect results, altered results, or a potential data breach”.

CISA’s advisory reveals that Illumina Universal Copy Service is affected by a critical vulnerability, tracked as CVE-2023-1968, related to binding to an unrestricted IP, which can allow an unauthenticated attacker to abuse the component to listen on all IPs, including ones that accept remote connections.

The second flaw, CVE-2023-1966, is related to unnecessary privileges that can allow an unauthenticated hacker to remotely upload and execute code at the OS level.

Illumina’s iScan, iSeq, MiniSeq, MiSeq, MiSeqDx, NextSeq, and NovaSeq products are affected by the vulnerabilities. These products, used worldwide in the healthcare sector, are designed for clinical diagnostic use in sequencing a person’s DNA for various genetic conditions or for research purposes.

“On April 5, 2023, Illumina sent notifications to affected customers instructing them to check their instruments and medical devices for signs of potential exploitation of the vulnerability,” the FDA said in its notification.

Similar notifications were issued last year by CISA and the FDA over different vulnerabilities affecting Illumina genetic analysis devices.

The FDA announced recently that it will require medical device makers to meet specific cybersecurity requirements when submitting an application for a new product.

Related: FDA Approves Use of New Tool for Medical Device Vulnerability Scoring

Related: Canon Medical Product Vulnerabilities Expose Patient Information

Related: Medical, IoT Devices From Many Manufacturers Affected by ‘Access:7’ Vulnerabilities

https://www.securityweek.com/fda-cisa-illumina-medical-devices-vulnerable-to-remote-hacking/




Critical Vulnerability in Zyxel Firewalls Leads to Command Execution

Taiwanese network equipment manufacturer Zyxel this week announced patches for a critical-severity vulnerability impacting its ATP, USG FLEX, VPN, and ZyWALL/USG firewalls.

Tracked as CVE-2023-28771 (CVSS score of 9.8), the security defect can be exploited remotely to execute OS commands.

“Improper error message handling in some firewall versions could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device,” Zyxel explains in its advisory.

The bug impacts ATP, USG FLEX, and VPN firmware versions 4.60 to 5.35, and ZyWALL/USG firmware versions 4.60 to 4.73. Fixes were included in ATP, USG FLEX, and VPN firmware releases 5.36 and ZyWALL/USG firmware version 4.73 Patch 1.

Users are advised to update their firewalls as soon as possible. While the vulnerability does not appear to be exploited in malicious attacks, unpatched Zyxel appliances are known to be targeted by malicious actors.

The firmware updates for ATP, USG FLEX, and VPN firewalls also resolve a high-severity command injection issue. Tracked as CVE-2023-27991, the vulnerability was addressed in USG FLEX 50(W) / USG20(W)-VPN firewalls as well (in firmware version 5.36).

This week, the company also announced fixes for several high-severity flaws in multiple firewalls and access point (AP) models, which could be exploited to cause denial-of-service (DoS) conditions, execute commands, cause a core dump, or retrieve encrypted information of the administrator.

Zyxel resolved the bugs with firmware updates for the impacted firewalls. Firmware updates were released for many AP devices as well, while for others hotfixes are available by request.

Users should review Zyxel’s advisory on these vulnerabilities and update their devices if necessary.

Related: Zyxel Patches Critical Vulnerability in NAS Firmware

Related:Technical Details Released for Recently Patched Zyxel Firewall Vulnerabilities

Related:Zyxel Warns Customers of Attacks on Security Appliances

https://www.securityweek.com/critical-vulnerability-in-zyxel-firewalls-leads-to-command-execution/




Microsoft: Cl0p Ransomware Exploited PaperCut Vulnerabilities Since April 13

A Cl0p ransomware operator affiliated with the FIN11 and TA505 threat actors has been exploiting recently patched PaperCut vulnerabilities since April 13, Microsoft says.

Impacting the PaperCut MF/NG print management system and tracked as CVE-2023-27350 (CVSS score of 9.8), the issue can be exploited to bypass authentication and achieve remote code execution (RCE) with System privileges.

PaperCut MF and PaperCut NG versions 20.1.7, 21.2.11 and 22.0.9 that were released in March 2023 address the critical-severity flaw along with CVE-2023–27351, a high-severity bug leading to information exposure.

Last week, PaperCut warned that CVE-2023-27350 has been exploited in malicious attacks, urging customers to update their installations as soon as possible.

Several days later, endpoint and response security firm Huntress said that it identified hundreds of vulnerable hosts with PaperCut installed and that it observed attackers exploiting the vulnerabilities to deploy remote management and maintenance (RMM) tools for persistent access.

While PaperCut has only mentioned CVE-2023-27350 being exploited in attacks, Huntress and Microsoft suggested that both vulnerabilities have been leveraged by hackers.

Huntress linked the attacks to TrueBot malware operator Silence, which is known to have ties with Russian hacking group TA505, which is known for distributing the Cl0p ransomware.

Now, Microsoft says that the Cl0p ransomware operator it tracks as Lace Tempest (also known as DEV-0950) – which is associated with both FIN11 and TA505 advanced persistent threat (APT) actors – has been exploiting the PaperCut vulnerabilities for the past two weeks.

“Lace Tempest (DEV-0950) is a Cl0p ransomware affiliate that has been observed using GoAnywhere exploits and Raspberry Robin infection hand-offs in past ransomware campaigns. The threat actor incorporated the PaperCut exploits into their attacks as early as April 13,” Microsoft says.

Microsoft also says that the threat actor executed PowerShell commands to drop TrueBot on vulnerable systems, confirming Huntress’ observations. The malware was observed attempting to steal Local Security Authority Subsystem Service (LSASS) credentials.

“Next, Lace Tempest delivered a Cobalt Strike Beacon implant, conducted reconnaissance on connected systems, and moved laterally using WMI. The actor then identified and exfiltrated files of interest using the file-sharing app MegaSync,” Microsoft notes.

According to Huntress, more threat actors are now exploiting the PaperCut vulnerabilities, including in attacks deploying cryptocurrency miners on compromised systems.

Related: GoAnywhere MFT Zero-Day Exploitation Linked to Ransomware Attacks

Related: Russia-Linked TA505 Back at Targeting Financial Institutions

Related: FIN11 Spun Out From TA505 Umbrella as Distinct Attack Group

https://www.securityweek.com/microsoft-cl0p-ransomware-exploited-papercut-vulnerabilities-since-april-13/




FIN7 Hackers Caught Exploiting Recent Veeam Vulnerability

Russian cybercrime group FIN7 has been observed exploiting unpatched Veeam Backup & Replication instances in recent attacks, cybersecurity company WithSecure reports.

Around since at least 2015 and also referred to as Anunak, and Carbanak, FIN7 is a financially motivated group mainly focused on credit card information theft. Security researchers believe there are numerous sub-groups operating under the FIN7 umbrella.

Over the past years, some of the threat actors overlapping with FIN7 operations were seen transitioning to ransomware, including REvil, DarkSide, BlackMatter, Alphv, and Black Basta.

At the end of March 2023, WithSecure caught FIN7 attacks that exploited internet-facing servers running Veeam Backup & Replication software to execute payloads on the compromised environment.

The cybersecurity firm observed a Veeam Backup process executing a shell command to download and execute a PowerShell script that turned out to be the Powertrash in-memory dropper known to be used by FIN7.

The dropper was used to drop Diceloader, a backdoor also known as Lizar, which enables attackers to perform various post-exploitation operations, and which has been linked to FIN7 before.

“The exact method used by the threat actor to invoke the initial shell commands remains unknown but was likely achieved through a recently patched Veeam Backup & Replication vulnerability, CVE-2023-27532, which can provide unauthenticated access to a Veeam Backup & Replication instance,” WithSecure says.

CVE-2023-27532 (CVSS score of 7.5) was disclosed and patched in early March. Roughly two weeks later, proof-of-concept (PoC) exploitation code targeting the vulnerability was released publicly.

According to Veeam, successful exploitation of the bug allows an attacker to obtain encrypted credentials that are stored in the configuration database. However, penetration testing firm Horizon3.ai, which released the PoC, says that the flaw allows attackers to obtain cleartext credentials.

As part of the observed FIN7 attacks, WithSecure identified suspicious activity targeting the exploited Veeam backup instances days before payloads were dropped, likely to probe and identify vulnerable servers.

The threat actor was seen performing network reconnaissance, stealing information from the Veeam backup database, exfiltrating stored credentials, achieving persistence for the Diceloader backdoor, and moving laterally using the stolen credentials.

“WithSecure Intelligence has so far identified two instances of such attacks conducted by FIN7. As the initial activity across both instances were initiated from the same public IP address on the same day, it is likely that these incidents were part of a larger campaign. However, given the probable rarity of Veeam backup servers with TCP port 9401 publicly exposed, we believe the scope of this attack is limited,” WithSecure notes.

CVE-2023-27532 was addressed with the release of Veeam Backup & Replication versions 12 (build 12.0.0.1420 P20230223) and 11a (build 11.0.1.1261 P20230227), which organizations need to install on the Veeam Backup & Replication server.

Vulnerabilities in Veeam’s product have been exploited in previous attacks and organizations are advised to update their Backup & Replication instances as soon as possible.

Related:CISA Warns Veeam Backup & Replication Vulnerabilities Exploited in Attacks

Related: New ‘Domino’ Malware Linked to FIN7 Group, Ex-Conti Members

Related:FIN7 Cybercrime Operation Continues to Evolve Despite Arrests

https://www.securityweek.com/fin7-hackers-caught-exploiting-recent-veeam-vulnerability/




SLP Vulnerability Allows DoS Attacks With Amplification Factor of 2,200

A high-severity vulnerability in the Service Location Protocol (SLP) can be exploited to launch denial-of-service (DoS) attacks with a high amplification factor, security researchers at Bitsight and Curesec warn.

A legacy internet protocol created in 1997, SLP is used for local network service discovery, without prior configuration, and can be scaled from small to large enterprise networks. The protocol was not intended to be exposed to the public internet.

Tracked as CVE-2023-29552 (CVSS score of 8.6), the newly disclosed vulnerability exists because SLP allows unauthenticated, remote attackers to register arbitrary services.

“This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor,” a NIST advisory explains.

The vulnerability allows for a DoS amplification factor of 2,200, Bitsight says. This is possible because attackers could combine a typical reflective DoS amplification attack with service registration to increase the amount of traffic sent to the victim.

“Assuming a 29-byte request, the amplification factor is roughly between 1.6X and 12X. However, SLP allows an unauthenticated user to register arbitrary new services, meaning an attacker can manipulate both the content and the size of the server reply, resulting in a maximum amplification factor of over 2200X due to the roughly 65,000-byte response given a 29-byte request,” Bitsight explains.

To exploit the vulnerability for DoS amplification, an attacker needs to find an SLP server on UDP port 427, register services until SLP denies more entries, send a request to the service by spoofing the victim’s IP as the origin, and then repeat the last step while the attack is ongoing.

“Depending on the software and/or system being used, the size of the reply can potentially reach the practical limit of a single UDP packet, which is typically 65,536 bytes,” Bitsight notes.

In February 2023, more than 2,000 global companies were using SLP, with over 54,000 SLP instances found to be accessible from the internet. According to Curesec, currently there are roughly 34,000 exploitable systems with SLP.

Bitsight says it has identified vulnerable instances belonging to Fortune 1000 organizations in the finance, insurance, healthcare, hospitality, manufacturing, technology, telecommunications, and transportation sectors.

More than 670 different product types were found vulnerable, including IBM Integrated Management Module (IMM), HP printers, Konica Minolta printers, Planex routers, VMware ESXi servers, and many others.

On Tuesday, VMware warned that, while currently supported ESXi releases (ESXi 7.x and 8.x) are not impacted by CVE-2023-29552, releases that are no longer supported, such as 6.7 and 6.5, are vulnerable. Customers are advised to upgrade to a supported release as soon as possible.

According to Cloudflare and Netscout, SLP is likely to soon be abused to amplify distributed denial-of-service (DDoS) attacks, unless organizations take the necessary precautions to secure the SLP instances they use.

Disabling SLP on systems running on untrusted networks should prevent exploitation of CVE-2023-29552. Setting firewall rules to filter traffic on UDP and TCP port 427 should also mitigate the risks associated with the flaw.

On Tuesday, the US Cybersecurity and Infrastructure Security Agency (CISA) urged network administrators to review the available information on CVE-2023-29552 and to “consider disabling or restricting network access to SLP servers” to prevent exploitation.

Related:Mitel Devices Abused for DDoS Vector With Record-Breaking Amplification Ratio

Related: DDoS Attacks Abuse Network Middleboxes for Reflection, Amplification

Related: Researchers Show How Censorship Systems Can Be Abused for DDoS Amplification

https://www.securityweek.com/slp-vulnerability-allows-dos-attacks-with-amplification-factor-of-2200/




Organizations Warned of Security Risk in Default Apache Superset Configurations

Malicious attackers can exploit Apache Superset installations running default configurations to gain administrator access and execute code on servers and databases, penetration testing firm Horizon3.ai warns.

An open source application written in Python and based on the Flask web framework, Apache Superset provides users with the ability to explore and visualize large amounts of data.

The same as other Flask-based applications, Superset uses session cookies that are signed with a secret key for authentication. 

The secret key is supposed to be randomly generated, to prevent scenarios where an attacker could use a known key to sign their own cookies and gain access to the application.

An attacker who knows a Superset session key could log in as an administrator, access databases connected to the application, add, modify or delete databases, and execute code remotely, both on databases and on the server.

“By default, database connections are set up with read-only permissions but an attacker with admin access can enable writes and DML (data model language) statements. The powerful SQL Lab interface allows attackers to run arbitrary SQL statements against connected databases,” Horizon3.ai explains.

Furthermore, the attacker could harvest sensitive information, including user password hashes and database credentials in plaintext.

Tacked as CVE-2023-27524 (CVSS score of 8.9), the vulnerability identified by Horizon3.ai exists because, when Superset is installed, the secret key is defaulted to a specific value, with the user being responsible for changing it to a cryptographically secure random string.

The security firm initially discovered and reported the bug in October 2021. The secret key value was rotated in January 2022 to a new default and a warning was added to the logs.

In February 2023, Horizon3.ai discovered that there were over 3,000 Superset instances accessible from the internet, and that more than 2,000 of them (roughly two thirds) were using a default secret key. Apache Superset versions up to 2.0.1 are impacted.

“Among the 2000+ affected users, we found a broad mix of large corporations, small companies, government agencies, and universities. We sent out good-faith notifications to a number of organizations, some of whom remediated shortly after,” the company notes.

The vulnerability was addressed in Superset version 2.1, which prevents the server from starting if a default secret key is in use. Superset instances that are installed via a docker-compose file or a helm template, however, still use default keys.

Other Flask-based applications were also found vulnerable to the hardcoded secret key bug, including Apache Airflow (CVE-2020-17526) and Redash (CVE-2021-41192).

Related: Critical Apache Commons Text Flaw Compared to Log4Shell, But Not as Widespread

Related:High-Severity Vulnerability Found in Apache Database System Used by Major Firms

Related:High-Risk Flaw Haunts Apache Server

https://www.securityweek.com/organizations-warned-of-security-risk-in-default-apache-superset-configurations/




VMware Patches Critical Vulnerability Disclosed at Pwn2Own Hacking Contest

VMware this week announced patches for a critical-severity vulnerability in Workstation and Fusion that was disclosed in March 2023 at the Pwn2Own Vancouver hacking contest.

Tracked as CVE-2023-20869 (CVSS score of 9.3), the issue was discovered by Star Labs researchers, who earned an $80,000 bug bounty reward for the finding.

VMware’s advisory describes the security defect as a stack-based buffer overflow bug in the “functionality for sharing host Bluetooth devices with the virtual machine”.

A malicious attacker that has local administrative privileges on a virtual machine could exploit the flaw to execute code on the host as the virtual machine’s VMX process.

VMware addressed the vulnerability with the release of Workstation version 17.0.2 and Fusion version 13.0.2.

The updates for Workstation and Fusion also address three high-severity vulnerabilities that could lead to information leaks, privilege escalation, and code execution.

The first is CVE-2023-20870, an out-of-bounds read flaw impacting the Bluetooth device-sharing functionality of VMware Workstation and Fusion, and which could allow a threat actor to read privileged information from the hypervisor memory.

Successful exploitation of the bug requires local administrator privileges to the virtual machine.

The second issue is CVE-2023-20871, a local privilege escalation vulnerability in VMware Fusion that could allow an attacker with read/write access to the host operating system to escalate their privileges to those of the ‘root’ user.

VMware also addressed an out-of-bounds read/write issue in the SCSI CD/DVD device emulation functionality of the two virtualization solutions. Tracked as CVE-2023-20872, the flaw was addressed in Workstation version 17.0.1 and Fusion version 13.0.1.

“A malicious attacker with access to a virtual machine that has a physical CD/DVD drive attached and configured to use a virtual SCSI controller may be able to exploit this vulnerability to execute code on the hypervisor from a virtual machine,” VMware explains.

Customers are advised to apply the available patches as soon as possible. While VMware made no mention of any of these vulnerabilities being exploited in malicious attacks, unpatched VMware products are known to have been targeted in attacks.

Related:VMware Patches Pre-Auth Code Execution Flaw in Logging Product

Related:Exploitation of Critical Vulnerability in End-of-Life VMware Product Ongoing

Related: VMware Plugs Critical Carbon Black App Control Flaw

https://www.securityweek.com/vmware-patches-critical-vulnerability-disclosed-at-pwn2own-hacking-contest/




Huntress: Most PaperCut Installations Not Patched Against Already-Exploited Security Flaw

Most Windows and macOS PaperCut installations have not been patched against a critical-severity vulnerability already exploited in attacks, according to a warning from endpoint and response security firm Huntress.

The security defect, tracked as CVE-2023-27350 (CVSS 9.8/10), is described as an improper access control bug in the PaperCut MF/NG print management system. Attackers can exploit the flaw to bypass authentication and execute arbitrary code remotely, with the privileges of the ‘System’ user.

In March 2023, PaperCut patched the vulnerability with the release of PaperCut MF and PaperCut NG versions 20.1.7, 21.2.11, and 22.0.9. Last week, the company warned that the issue was already exploited in malicious attacks, urging customers to update installations immediately.

Despite the urgency to update, however, most PaperCut MF/NG customers have yet to apply the available patches, Huntress said in a new report.

In the environments it protects, Huntress has identified more than 1,000 Windows hosts with PaperCut installed. Among them, there are over 900 vulnerable versions, spread across about 700 organizations.

The company also identified three macOS hosts with PaperCut Server installed and says that two of them are running vulnerable versions. While PaperCut installations should not be accessible from the internet, a Shodan search shows that there are at least 1,800 publicly accessible PaperCut servers.

Exploitation of the critical PaperCut vulnerability, Huntress warns, started days before PaperCut’s advisory and patch, with the attackers deploying copies of the legitimate Atera and Syncro remote management and maintenance (RMM) applications for persistent access to the vulnerable systems.

While analyzing a domain observed in these attacks, Huntress researchers identified a Windows DLL that proved to be a variant of the Truebot malware, a post-exploitation tool linked to Silence, a threat actor known to be associated with Russian hacking group TA505 – the threat actor behind the Cl0p ransomware.

While the ultimate goal of the current activity leveraging PaperCut’s software is unknown, these links (albeit somewhat circumstantial) to a known ransomware entity are concerning. Potentially, the access gained through PaperCut exploitation could be used as a foothold leading to follow-on movement within the victim network, and ultimately ransomware deployment,” Huntress notes.

The security firm also performed an analysis of vulnerable versions of PaperCut MF/NG and discovered that, once the print management solution has been installed, authentication can be bypassed by simply navigating to the ‘SetupCompleted’ page.

Without knowing any credentials, an attacker could exploit the bug to log in as an administrator, gaining access to all configurations and settings. The attacker could then make several tweaks to disable PaperCut MF/NG’s sandbox and have Java code executed on the server.

The cybersecurity firm has created a working proof-of-concept (PoC) that demonstrates both how authentication can be bypassed and how code can be executed remotely on vulnerable PaperCut servers.

Last week, the US Cybersecurity and Infrastructure Security Agency (CISA) added the PaperCut MF/NG vulnerability to its Known Exploited Vulnerabilities list. 

Related: GoAnywhere MFT Zero-Day Exploitation Linked to Ransomware Attacks

Related: Russia-Linked TA505 Back at Targeting Financial Institutions

Related: FIN11 Spun Out From TA505 Umbrella as Distinct Attack Group

https://www.securityweek.com/huntress-most-papercut-installations-not-patched-against-already-exploited-security-flaw/