Several High-Severity Vulnerabilities Expose Cisco Firewalls to Remote Attacks
Cisco this week released patches for multiple vulnerabilities in Firepower Threat Defense (FTD) software, including high-severity issues that could be exploited for arbitrary command execution or denial-of-service (DoS) attacks.
Tracked as CVE-2021-1448 and having a CVSS score of 7.8, the command injection bug is mitigated by the fact that authentication and local access are required for successful exploitation. An attacker able to abuse it, however, may execute arbitrary commands as root on the underlying OS.
The flaw exists because user-supplied command arguments aren’t sufficiently validated, and affects Firepower 4100 and Firepower 9300 series appliances. No workarounds exist, but software updates to address the vulnerability are already available.
Another flaw rooted in insufficient validation impacts the software-based SSL/TLS message handler of FTD and could be abused to cause a DoS condition. The security hole is tracked as CVE-2021-1402 (CVSS score of 8.6).
Remote, unauthenticated attackers could exploit this vulnerability by sending a “crafted SSL/TLS message through an affected device.” However, messages that are sent to the affected device won’t trigger the bug, Cisco notes.
Affected devices include 3000 series industrial security appliances (ISAs), ASA 5512-X/ASA 5515-X/ASA 5525-X/ASA 5545-X/ASA 5555-X adaptive security appliances, Firepower 1000/2100 series, and Firepower Threat Defense Virtual (FTDv) products.
Four other DoS bugs addressed this week in FTD also impact Cisco Adaptive Security Appliance (ASA) software and could all be exploited remotely. Three of them (CVE-2021-1445, CVE-2021-1504, and CVE-2021-1501, CVSS score of 8.6) do not require authentication, while the fourth (CVE-2021-1493, CVSS score of 8.5) does.
Cisco says it is not aware of these vulnerabilities being exploited in attacks in the wild, but nonetheless recommends installing the available patches as soon as possible, to avoid possible cyber-security incidents.
Patches the tech giant released this week also address multiple medium-severity issues, including four in FTD software (two impact ASA software too), five in Firepower Management Center (FMC), one in Firepower Device Manager (FDM), and one in the Snort detection engine that affects multiple products.
Information on all of these vulnerabilities and on the patches released for them is available on Cisco’s security portal.
Google Patches Yet Another Serious V8 Vulnerability in Chrome
An update released this week by Google for Chrome 90 patches yet another serious vulnerability affecting the V8 JavaScript engine used by the web browser.
The flaw, tracked as CVE-2021-21227 and rated high severity, was reported to Google by researcher Gengming Liu from Chinese cybersecurity firm Singular Security Lab.
The researcher earned $15,000 for reporting the vulnerability, which Google described as “insufficient data validation in V8.”
Liu told SecurityWeek that the flaw can be exploited for remote code execution in the targeted user’s browser, but noted that, similar to other recently disclosed V8 vulnerabilities, it does not escape the Chrome sandbox — a sandbox escape bug is needed to exploit CVE-2021-21227 in real world attacks.
The hacker says CVE-2021-21227 is related to CVE-2020-16040 and CVE-2020-15965, similar high-severity V8 vulnerabilities that Google patched in Chrome in December and September 2020, respectively.
CVE-2020-16040 and CVE-2020-15965 were reported to Google by Lucas Pinheiro of Microsoft Browser Vulnerability Research. Liu discovered CVE-2021-21227 while analyzing the patches for the two vulnerabilities found by Pinheiro — he says they all impact the same function.
Google has patched several serious V8 vulnerabilities in recent weeks, including some for which PoC exploits were released before patches were made available. For some of these security holes, Google warned that exploits exist in the wild.
The Chrome 90 update released this week (version 90.0.4430.93) includes 9 security fixes, including for a couple of other high-severity issues, three medium-severity bugs, and one low-severity vulnerability. Bug bounty amounts are not listed, except for a medium-severity insufficient policy enforcement issue reported by researcher Rob Wu, who earned $5,000 for his findings.
Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
Fraud prevention technology provider Sift is now the 11th cybersecurity company to reach “unicorn” status in 2021, following a new $50 million round of venture capital funding.
Sift, which rebranded itself in January 2019 by dropping “Science” from “Sift Science,” says it plans to use the new injection of cash to continue expanding its product portfolio, as well as to hire new talent to scale product, engineering, and sales teams globally.
The San Francisco, California-based company provides organizations with the necessary tools to identify fraud patterns, helping them prevent payment fraud, account hijacking, and other forms of abuse. In 2020, Sift’s Digital Trust & Safety platform processed in excess of $250 billion in transactions.
The round was led by Insight Partners, with participation from Union Square Ventures and Stripe, and brings the total raised to date by Sift to $158 million, as well as the company’s valuation at above $1 billion.
“With this new investment we can continue to build out our Digital Trust & Safety platform to help merchants not only fight all types of fraud and abuse, but reduce friction for legitimate customers and grow revenue,” said Marc Olesen, president and CEO at Sift.
Vulnerabilities in Eaton Product Can Allow Hackers to Disrupt Power Supply
Power management solutions provider Eaton has released patches for its Intelligent Power Manager (IPM) software to address several potentially serious vulnerabilities, including ones that researchers say could allow hackers to disrupt power supply.
Eaton’s IPM solution is designed to ensure system uptime and data integrity by allowing organizations to remotely monitor, manage and control the uninterruptible power supply (UPS) devices on their network.
According to security advisories published this month by Eaton and the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the IPM product is affected by six high-severity vulnerabilities that can be exploited for SQL injection, command execution, deleting arbitrary files, uploading arbitrary files, and remote code execution.
While some of the vulnerabilities can only be exploited by an authenticated attacker, others can be exploited without authentication, including for arbitrary code execution.
Amir Preminger, VP of research at industrial cybersecurity firm Claroty, who has been credited by Eaton for reporting the six vulnerabilities, told SecurityWeek that the issues were identified in a web server interface of the IPM software that enables users to configure the product. This web server is typically accessible from the local network and is not hosted on public-facing servers.
“The goal of the Eaton IPM software is to enable users to manage their UPS system. By exploiting a server using this software, an attacker can disrupt the UPS operations and therefore disrupt the power supply to equipment that relies on the UPS as its power source,” Preminger explained.
He added, “The bottom line is that this product should be patched, since a few of the CVEs are pre-auth and could be exploited by adversaries without prior knowledge about the server setup.”
The security holes impact Eaton IPM and Intelligent Power Manager Virtual Appliance (IPM VA) running versions prior to 1.69, and Intelligent Power Protector (IPP) running versions prior to 1.68. Versions 1.69 and 1.68 address the vulnerabilities. Organizations can also block ports 4679 and 4680 to prevent exploitation.
Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
Actively exploited Mac 0-day neutered core OS security defenses
Getty Images
When Apple released the latest version 11.3 for macOS on Monday, it didn’t just introduce support for new features and optimizations. More importantly, the company fixed a zero-day vulnerability that hackers were actively exploiting to install malware without triggering core Mac security mechanisms, some that were in place for more than a decade.
Together, the defenses provide a comprehensive set of protections designed to prevent users from inadvertently installing malware on their Macs. While one-click and even zero-click exploits rightfully get lots of attention, it’s far more common to see trojanized apps that disguise malware as a game, update, or other desirable piece of software.
Protecting users from themselves
Apple engineers know that trojans represent a bigger threat to most Mac users than more sophisticated exploits that surreptitiously install malware with minimal or no interaction from users. So a core part of Mac security rests on three related mechanisms:
File Quarantine requires explicit user confirmation before a file downloaded from the Internet can execute.
Gatekeeper blocks the installation of apps unless they’re signed by a developer known to Apple.
Mandatory App Notarization permits apps to be installed only after Apple has scanned them for malware.
Earlier this year, a piece of malware well known to Mac security experts began exploiting a vulnerability that allowed it to completely suppress all three mechanisms. Called Shlayer, it has an impressive record in the three years since it appeared.
Last September, for instance, it managed to pass the security scan that Apple requires for apps to be notarized. Two years ago, it was delivered in a sophisticated campaign that used novel steganography to evade malware detection. And last year, Kaspersky said Shlayer was the most detected Mac malware by the company’s products, with almost 32,000 different variants identified.
Clever evasion
Shlayer’s exploitation of the zero-day, which started no later than January, represented yet another impressive feat. Rather than using the standard Mach-O format for a Mac executable, the executable component in this attack was the macOS script, which executes a series of line commands in a particular order.
Normally, scripts downloaded from the Internet are classified as application bundles and are subject to the same requirements as other types of executables. A simple hack, however, allowed scripts to completely shirk those requirements.
By removing the info.plist—a structured text file that maps the location of files it depends on—the script no longer registered as an executable bundle to macOS. Instead, the file was treated as a PDF or other type of non-executable file that wasn’t subject to Gatekeeper and the other mechanisms.
One of the attacks began with the display of an ad for a fake Adobe Flash update:
The videos below show what a big difference the exploit made once someone took the bait and clicked download. The video immediately below depicts what the viewer saw with the restrictions removed. The one below that shows how much more suspicious the update would have looked had the restrictions been in place.
[embedded content]
Shlayer attack with exploit of CVE-2021-30657.
[embedded content]
Shlayer attack without exploit of CVE-2021-30657.
The bug, which is tracked as CVE-2021-30657, was discovered and reported to Apple by security researcher Cedric Owens. He said he stumbled upon it as he was using a developer tool called Appify while performing research for a “red team” exercise, in which hackers simulate a real attack in an attempt to find previously overlooked security weaknesses.
“I found that Appify was able to turn a shell script into a double clickable ‘app’ (really just a shell script inside of the macOS app directory structure but macOS treated it as an app),” he wrote in a direct message. “And when executed it bypasses Gatekeeper. I actually reported it pretty quickly after discovering it and did not use it in a live red team exercise.”
Apple fixed the vulnerability with Monday’s release of macOS 11.3. Owens said that the flaw appears to have existed since the introduction of macOS 10.15 in June 2019, which is when notarization was introduced.
Owens discussed the bug with Patrick Wardle, a Mac security expert who previously worked at Jamf, a Mac enterprise security provider. Wardle then reached out to Jamf researchers, who uncovered the Shlayer variant that was exploiting the vulnerability before it was known to Apple or most of the security world.
“One of our detections alerted us to this new variant, and upon closer inspection we discovered its use of this bypass to allow it to be installed without an end user prompt,” Jamf researcher Jaron Bradley told me. “Further analysis leads us to believe that the developers of the malware discovered the zeroday and adjusted their malware to use it, in early 2021.”
Wardle developed a proof-of-concept exploit that showed how the Shlayer variant worked. After being downloaded from the Internet, the executable script appears as a PDF file named Patrick’s Resume. Once someone doubleclicks on the file, it launches a file called calculator.app. The exploit could just as easily execute a malicious file.
Patrick Wardle
In a 12,000-word deep-dive that delves into the causes and effects of the exploits, Wardle concluded:
Though this bug is now patched, it clearly (yet again) illustrates that macOS is not impervious to incredible shallow, yet hugely impactful flaws. How shallow? Well that fact that a legitimate developer tool (appify) would inadvertently trigger the bug is beyond laughable (and sad).
And how impactful? Basically macOS security (in the context of evaluating user launched applications, which recall, accounts for the vast majority of macOS infections) was made wholly moot.
Bradley published a post that recounted how the exploit looked and worked.
Many people consider malware like Shlayer unsophisticated because it relies on tricking its victims. To give Shlayer its due, the malware is highly effective, in large part because of its ability to suppress macOS defenses designed to tip-off users before they accidentally infect themselves. Those who want to know if they’ve been targeted by this exploit can download this python script written by Wardle.
https://arstechnica.com/?p=1760304
Apple Patches macOS Security Bypass Vulnerability Exploited by ‘Shlayer’ Malware
Apple has patched a serious security bypass vulnerability in macOS that has been exploited in the wild by at least one threat group.
The tech giant on Monday informed customers that it has patched tens of vulnerabilities in macOS Catalina, Mojave and Big Sur. The Big Sur update fixes nearly 60 security holes, including a logic issue tracked as CVE-2021-30657 that, Apple says, can allow a malicious application to bypass Gatekeeper checks.
macOS has three main security mechanisms designed to protect users against malicious files downloaded from the internet: file quarantine, which prompts the user and asks for confirmation when executing a file; Gatekeeper, which checks code-signing information to ensure an application comes from a trusted developer and it has not been tampered with; and notarization, which involves automatically scanning software for malicious content before it is allowed to run.
The vulnerability tracked as CVE-2021-30657 can be exploited to bypass file quarantine, Gatekeeper and notarization using specially crafted applications. Specifically, a script-based application that does not contain an “Info.plist” configuration file is misclassified by Apple’s security mechanisms and is allowed to run without prompting the user.
Apple has credited “an anonymous researcher” for reporting the bug, but the issue was apparently reported to the tech giant by researcher Cedric Owens on March 25. Owens on Monday published a blog post detailing his findings. He also pointed out that an open source application named appify, which allows users to create “the simplest possible Mac app from a shell script,” has been generating apps that unintentionally exploit the vulnerability.
Patrick Wardle, a researcher who specializes in the security of Apple products, published a lengthy blog post on Monday to describe the vulnerability and its root cause in detail. Wardle has created a proof-of-concept (PoC) exploit that is disguised as a harmless PDF document and which executes an application on the compromised device when opened, without the user seeing any warnings.
The researcher said the vulnerability was apparently introduced in macOS 10.15 and older versions of the operating system do not seem to be affected. Apple only patched the issue in macOS Big Sur.
“Though this bug is now patched, it clearly (yet again) illustrates that macOS is not impervious to incredible shallow, yet hugely impactful flaws. How shallow? Well that fact that a legitimate developer tool (appify) would inadvertently trigger the bug is beyond laughable (and sad).” Wardle said.
Wardle has asked Apple device management company Jamf — Jamf in 2019 acquired a Mac endpoint security company founded by Wardle — to look for threats that may have abused this weakness in the wild. Sure enough, Jamf researchers discovered that a variant of the Shlayer malware, which drops adware on infected devices, had been leveraging the vulnerability since at least January 9, 2021, to bypass the file quarantine, notarization and Gatekeeper.
In the attacks observed by Jamf, hackers had used poisoned search engine results to deliver the malware. The developers of Shlayer have been known to come up with clever ways to bypass Apple security mechanisms. Last year, they were spotted delivering notarized exploits.
Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
In epic hack, Signal developer turns the tables on forensics firm Cellebrite
For years, Israeli digital forensics firm Cellebrite has helped governments and police around the world break into confiscated mobile phones, mostly by exploiting vulnerabilities that went overlooked by device manufacturers. Now, Moxie Marlinspike—creator of the Signal messaging app—has turned the tables on Cellebrite.
On Wednesday, Marlinspike published a post that reported vulnerabilities in Cellebrite software that allowed him to execute malicious code on the Windows computer used to analyze devices. The researcher and software engineer exploited the vulnerabilities by loading specially formatted files that can be embedded into any app installed on the device.
Virtually no limits
“There are virtually no limits on the code that can be executed,” Marlinspike wrote.
He continued:
For example, by including a specially formatted but otherwise innocuous file in an app on a device that is then scanned by Cellebrite, it’s possible to execute code that modifies not just the Cellebrite report being created in that scan, but also all previous and future generated Cellebrite reports from all previously scanned devices and all future scanned devices in any arbitrary way (inserting or removing text, email, photos, contacts, files, or any other data), with no detectable timestamp changes or checksum failures. This could even be done at random, and would seriously call the data integrity of Cellebrite’s reports into question.
Cellebrite provides two software packages: The UFED breaks through locks and encryption protections to collect deleted or hidden data, and a separate Physical Analyzer uncovers digital evidence (“trace events”).
To do their job, both pieces of Cellebrite software must parse all kinds of untrusted data stored on the device being analyzed. Typically, software that is this promiscuous undergoes all kinds of security hardening to detect and fix any memory-corruption or parsing vulnerabilities that might allow hackers to execute malicious code.
“Looking at both UFED and Physical Analyzer, though, we were surprised to find that very little care seems to have been given to Cellebrite’s own software security,” Marlinspike wrote. “Industry-standard exploit mitigation defenses are missing, and many opportunities for exploitation are present.”
Compromising integrity
One example of this lack of hardening was the inclusion of Windows DLL files for audio/video conversion software known as FFmpeg. The software was built in 2012 and hasn’t been updated since. Marlinspike said that in the intervening nine years, FFmpeg has received more than 100 security updates. None of those fixes are included in the FFmpeg software bundled into the Cellebrite products.
Marlinspike included a video that shows UFED as it parses a file he formatted to execute arbitrary code on the Windows device. The payload uses the MessageBox Windows API to display a benign message, but Marlinspike said that “it’s possible to execute any code, and a real exploit payload would likely seek to undetectably alter previous reports, compromise the integrity of future reports (perhaps at random!), or exfiltrate data from the Cellebrite machine.”
Marlinspike said he also found two MSI installer packages that are digitally signed by Apple and appear to have been extracted from the Windows installer for iTunes. Marlinspike questioned if the inclusion constitutes a violation of Apple copyrights. Apple didn’t immediately provide a comment when asked about this.
In an email, a Cellebrite representative wrote: “Cellebrite is committed to protecting the integrity of our customers’ data, and we continually audit and update our software in order to equip our customers with the best digital intelligence solutions available.” The representative didn’t say if company engineers were aware of the vulnerabilities Marlinspike detailed or if the company had permission to bundle Apple software.
Marlinspike said he obtained the Cellebrite gear in a “truly unbelievable coincidence” as he was walking and “saw a small package fall off a truck ahead of me.” The incident does seem truly unbelievable. Marlinspike declined to provide additional details about precisely how he came into possession of the Cellebrite tools.
The fell-of-a-truck line wasn’t the only tongue-in-cheek statement in the post. Marlinspike also wrote:
In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. Files will only be returned for accounts that have been active installs for some time already, and only probabilistically in low percentages based on phone number sharding. We have a few different versions of files that we think are aesthetically pleasing, and will iterate through those slowly over time. There is no other significance to these files.
The vulnerabilities could provide fodder for defense attorneys to challenge the integrity of forensic reports generated using the Cellebrite software. Cellebrite representatives didn’t respond to an email asking if they were aware of the vulnerabilities or had plans to fix them.
“We are of course willing to responsibly disclose the specific vulnerabilities we know about to Cellebrite if they do the same for all the vulnerabilities they use in their physical extraction and other services to their respective vendors, now and in the future,” Marlinspike wrote.
Post updated to add fourth- and third-to-last paragraphs and to add comment from Cellebrite.
https://arstechnica.com/?p=1759092
Hackers are exploiting a Pulse Secure 0-day to breach orgs around the world
Hackers backed by nation-states are exploiting critical vulnerabilities in the Pulse Secure VPN to bypass two-factor authentication protections and gain stealthy access to networks belonging to a raft of organizations in the US Defense industry and elsewhere, researchers said.
At least one of the security flaws is a zero-day, meaning it was unknown to Pulse Secure developers and most of the research world when hackers began actively exploiting it, security firm Mandiant said in a blog post published Tuesday. Besides CVE-2021-22893, as the zero-day is tracked, multiple hacking groups—at least one of which likely works on behalf of the Chinese government—are also exploiting several Pulse Secure vulnerabilities fixed in 2019 and 2020.
Under siege
“Mandiant is currently tracking 12 malware families associated with the exploitation of Pulse Secure VPN devices,” researchers Dan Perez, Sarah Jones, Greg Wood, and Stephen Eckels wrote. “These families are related to the circumvention of authentication and backdoor access to these devices, but they are not necessarily related to each other and have been observed in separate investigations. It is likely that multiple actors are responsible for the creation and deployment of these various code families.”
Used alone or in concert, the security flaws allow the hackers to bypass both single-factor and multifactor authentication protecting the VPN devices. From there, the hackers can install malware that persists across software upgrades and maintain access through webshells, which are browser-based interfaces that allow hackers to remotely control infected devices.
Multiple intrusions over the past six months have hit defense, government, and financial organizations around the world, Tuesday’s post reported. Separately, the US Cybersecurity and Infrastructure Security Agency said that targets also include US government agencies, critical infrastructure entities, and other private sector organizations.”
Mandiant said that it has uncovered “limited evidence” that tied one of the hacker groups to the Chinese government. Dubbed UNC2630, this previously unknown team is one of at least two hacking groups known to be actively exploiting the vulnerabilities. Tuesday’s post said:
We observed UNC2630 harvesting credentials from various Pulse Secure VPN login flows, which ultimately allowed the actor to use legitimate account credentials to move laterally into the affected environments. In order to maintain persistence to the compromised networks, the actor utilized legitimate, but modified, Pulse Secure binaries and scripts on the VPN appliance. This was done to accomplish the following:
Trojanize shared objects with malicious code to log credentials and bypass authentication flows, including multifactor authentication requirements. We track these trojanized assemblies as SLOWPULSE and its variants.
Inject webshells we currently track as RADIALPULSE and PULSECHECK into legitimate Internet-accessible Pulse Secure VPN appliance administrative web pages for the devices.
Toggle the filesystem between Read-Only and Read-Write modes to allow for file modification on a typically Read-Only filesystem.
Maintain persistence across VPN appliance general upgrades that are performed by the administrator.
Unpatch modified files and delete utilities and scripts after use to evade detection.
Clear relevant log files utilizing a utility tracked as THINBLOOD based on an actor defined regular expression.
Mandiant provided the following diagrams showing the flow of various authentication bypasses and log access:
LDAP Auth Bypass.
Radius 2FA bypass.
ACE credential log.
ACE-authentication bypass variant.
Reamsignin 2FA bypass.
Tuesday’s blog post also referred to another previously unseen group that Mandiant is calling UNC2717. In March, the group used malware Mandiant identifies as RADIALPULSE, PULSEJUMP, and HARDPULSE against Pulse Secure systems at a European organization.
The company researchers added:
Due to a lack of context and forensic evidence at this time, Mandiant cannot associate all the code families described in this report to UNC2630 or UNC2717. We also note the possibility that one or more related groups is responsible for the development and dissemination of these different tools across loosely connected APT actors. It is likely that additional groups beyond UNC2630 and UNC2717 have adopted one or more of these tools. Despite these gaps in our understanding, we included detailed analysis, detection techniques, and mitigations for all code families in the Technical Annex.
Two years (and counting) of insecurity
Over the past two years, Pulse Secure parent company Ivanti has released patches for a series of Pulse Secure vulnerabilities that not only allowed remote attackers to gain access without a username or password but also to turn off multifactor authentication and view logs, usernames, and passwords cached by the VPN server in plain text.
During that same time span, the critical vulnerabilities have come under active attack by hackers and likely led to the successful ransomware attack on Travelex, the foreign currency exchange and travel insurance company that neglected to install the patches.
The Mandiant advisory is concerning because it suggests that organizations in highly sensitive areas still haven’t applied the fixes. Also concerning is the revelation of a Pulse Secure zero-day that is under wide attack.
Pulse Secure on Tuesday published an advisory instructing users how to mitigate the currently unpatched security bug. The Mandiant blog post contains a wealth of technical indicators that organizations can use to determine if their networks have been targeted by the exploits.
Any organization that’s using Pulse Secure anywhere in its network should prioritize reading and following the recommendations from both Mandiant and Pulse Secure.
https://arstechnica.com/?p=1758789
Another Critical Vulnerability Patched in SAP Commerce
On Tuesday, as part of its April 2021 Security Patch Day, SAP announced the release of 14 new security notes and 5 updates to previously released notes. The only new Hot News note released with this round of patches addresses a critical vulnerability in SAP Commerce.
Tracked as CVE-2021-27602 and featuring a CVSS score of 9.9, the critical security hole could be abused to achieve remote code execution, SAP says.
The issue allows authorized users of the SAP Commerce Backoffice software to inject malicious code in source rules by abusing the scripting capabilities of the Rules engine.
“This can lead to a remote code execution with critical impact on the system’s confidentiality, integrity, and availability,” Onapsis, a firm that specializes in securing Oracle and SAP applications, explains.
To address the vulnerability, SAP introduced “additional validations and output encoding when processing rules.”
Two other Hot News security notes included in this month’s Security Patch Day are updates to previously released notes. The first of them is an update for the Chromium-based browser in SAP Business Client, while the second deals with a missing authorization check in NetWeaver AS JAVA.
SAP’s April 2021 Security Patch Day also saw the release of security notes for four high-severity flaws, namely three information disclosure issues in NetWeaver Master Data Management (CVE-2021-21482), Solution Manager (CVE-2021-21483), and NetWeaver AS for Java (CVE-2021-21485), and an unquoted service path in SAPSetup (CVE-2021-27608).
SAP also released an update for a high-severity note addressing CVE-2020-26832, a missing authorization check in NetWeaver AS ABAP and S4 HANA (SAP Landscape Transformation).
The remaining security notes, all with a severity rating of medium, address vulnerabilities in NetWeaver AS for Java, NetWeaver AS for ABAP, Process Integration (Integration Builder Framework), Process Integration (ESR Java Mappings), Manufacturing Execution (System Rules), Focused RUN, and HCM Travel Management Fiori Apps V2.
Four other vulnerabilities were addressed with security notes released between the March 2021 and April 2021 Security Patch Days.
Organizations are advised to apply the available patches as soon as possible, to ensure their applications remain protected. A study that SAP and Onapsis published last week revealed that, in some cases, threat actors start targeting newly patched vulnerabilities mere days after security updates are released.
Siemens Releases Several Advisories for ‘NAME:WRECK’ Vulnerabilities
Siemens released a total of 14 new advisories on Tuesday, including five describing the impact and remediations for the NAME:WRECK vulnerabilities disclosed on the same day.
IoT security company Forescout on Tuesday revealed that four popular TCP/IP stacks — specifically FreeBSD, Siemens’ Nucleus, IPnet and NetX — are affected by a total of nine DNS-related flaws that can be exploited for remote code execution (including to take control of targeted devices), DoS attacks, and DNS cache poisoning.
The vulnerabilities, collectively tracked as NAME:WRECK, could affect billions of devices that use these TCP/IP stacks for network communications, but Forescout researchers estimate that at least 100 million devices are exposed to attacks.
Siemens on Tuesday published several advisories related to NAME:WRECK: one advisory to describe two out-of-bounds write flaws that can lead to code execution or DoS attacks, another advisory for a DNS cache poisoning issue, one advisory for two DoS vulnerabilities, and two advisories for the same four DoS and DNS cache poisoning flaws (one is for impact on the SIMOTICS CONNECT 400 remote motor monitoring system).
Affected products include Nucleus 4, Nucleus NET, Nucleus RTOS, Nucleus ReadyStart, and VSTAR, as well as the Nucleus source code. Siemens has released patches for some of the impacted products and it has also provided workarounds and mitigations to reduce the risk until a patch can be installed or becomes available.
Forescout wrote in its report on the NAME:WRECK vulnerabilities, “According to the website of Nucleus RTOS(which runs the Nucleus TCP/IP stack), it is deployed in more than 3 billion devices. A quick look at Siemens’ page listing customer success stories reveals its use in scenarios such as healthcare (ZOLL defibrillators and ZONARE ultrasound machines), IT (BDT AG storage systems) and critical sys-tems (Garmin avionics navigation). But we believe that most of those 3 billion are actually device components such as MediaTek IoT chipsets and baseband processors used in smartphones and other wireless devices (which is similar to the distribution seen below for ThreadX).”
Siemens on Tuesday also published advisories for vulnerabilities affecting TIM 4R-IE, LOGO! Soft Comfort, Siveillance Video Open Network Bridge (ONVIF), Opcenter Quality, QMS Automotive, Control Center Server (CCS), Tecnomatix RobotExpert, SCALANCE X-200, Solid Edge, and SINEMA Remote Connect Server products.
Schneider Electric advisories
Schneider Electric on Tuesday published two new security advisories. One of them describes four high- and one medium-severity vulnerabilities affecting the C-Bus Toolkit, which is used to configure and commission C-Bus installations. The flaws, related to the handling of files, can be exploited for remote code execution.
The second advisory from Schneider describes a couple of old Windows vulnerabilities affecting its NTZ Mekhanotronika Rus control panels.
Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.