News: 1627539972

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Here's a list of the flaws Russia, China, Iran and pals exploit most often, say Five Eyes infosec agencies

(2021/07/29)


Western cybersecurity agencies have published a list of 30 of the most exploited vulnerabilities abused by hostile foreign states in 2020, urging infosec bods to ensure their networks and deployments are fully patched against them.

Number one on the US, UK, and Australia's jointly published

[1]PDF

list was the well-known Citrix [2]arbitrary code execution vuln in Application Delivery Controller, aka Netscaler load-balancer. Tracked as CVE-2019-19781, the vuln has been the subject of [3]repeated patch-it-now warnings ever since.

"In 2021, malicious cyber actors continued to target vulnerabilities in perimeter-type devices. Among those highly exploited in 2021 are vulnerabilities in Microsoft, Pulse, Accellion, VMware, and Fortinet," said the US's CISA and FBI, Britain's NCSC, and Australia's ACSC, three of the [4]Five Eyes alliance.

[5]

Second, third, and fourth on the agencies' list were, you guessed it, the [6]Pulse Secure VPN , Fortinet, and [7]F5 Big IP vulns . Regular readers of El Reg 's security pages can't have failed to notice that these are really quite bad and ought to have been patched months (or even years) ago.

[8]

[9]

Paul Chichester, NCSC Director for Operations, said: "We are committed to working with allies to raise awareness of global cyber weaknesses – and present easily actionable solutions to mitigate them. The advisory published today puts the power in every organisation’s hands to fix the most common vulnerabilities, such as unpatched VPN gateway devices."

[10]SolarWinds issues software update – one it wrote for a change – to patch hole exploited in the wild

[11]What follows Patch Tuesday? Exploit Wednesday. Grab this bumper batch of security updates from Microsoft

[12]You've patched that critical Sage X3 ERP security hole, yeah? Not exposing the suite to the internet, either, yeah?

[13]Microsoft struggles to wake from PrintNightmare: Latest print spooler patch can be bypassed, researchers say

Aside from the well-known VPN vulns are other common entry methods, such as exploitation of the [14]Netlogon escalation-of-privilege flaw , an RCE hole in software development framework Telerik that was [15]abused by the Chinese for attacks on Australia , and more.

And 2021 to date isn't much better

This year the picture is just as rosy. Enemies of the West gleefully bashed the button over the Microsoft Exchange vulns [16]exploited by China's Ministry of State Security .

Second to that were the aforementioned Pulse Secure VPN flaws, and vulns in Accellion file-transfer appliances that became a popular target for ransomware gangs – with their victims [17]even including infosec firm Qualys .

Along with that are critical RCE holes in VMware's vCenter product, [18]as we reported in May.

[19]

ACSC chief Abigail Bradshaw said in a canned comment: "This guidance will be valuable for enabling network defenders and organisations to lift collective defences against cyber threats. This advisory complements our advice available through cyber.gov.au and underscores the determination of the ACSC and our partner agencies to collaboratively combat malicious cyber activity."

The four agencies also gave some pragmatic advice for overworked sysadmins unable to immediately patch every single thing, perhaps for fear of KO'ing production networks through unforeseen side effects:

"If an organization is unable to update all software shortly after a patch is released, prioritize implementing patches for CVEs that are already known to be exploited or that would be accessible to the largest number of potential attackers (such as internet-facing systems)."

[20]

The full advisory, including detailed notes on each of the highlighted vulns, can be read on the Australian Cyber Security Centre's [21]website . ®

Get our [22]Tech Resources



[1] https://us-cert.cisa.gov/sites/default/files/publications/AA21-209A_Joint%20CSA_Top%20Routinely%20Exploited%20Vulnerabilities.pdf

[2] https://www.theregister.com/2019/12/23/patch_now_published_citrix_applications_leave_network_vulnerable_to_unauthorised_access/

[3] https://www.theregister.com/2020/09/14/chinas_hackers_f5_citrix/

[4] https://www.theregister.com/2020/10/11/international_statementon_end_to_end_encryption_and_public_safety/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQJ8Nvr5uDxoUdGZJPYcTwAAAEg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[6] https://www.theregister.com/2020/09/16/iran_targets_citrix_pulse_secure_f5_vpns/

[7] https://www.theregister.com/2020/07/03/f5_critical_flaws_big_ip/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQJ8Nvr5uDxoUdGZJPYcTwAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQJ8Nvr5uDxoUdGZJPYcTwAAAEg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2021/07/12/solarwinds_patch_attack/

[11] https://www.theregister.com/2021/07/14/patch_tuesday/

[12] https://www.theregister.com/2021/07/07/sage_x3_rce/

[13] https://www.theregister.com/2021/07/07/printnightmare_fix_fail/

[14] https://www.theregister.com/2020/09/24/microsoft_zerologon_in_wild/

[15] https://www.theregister.com/2020/06/19/australia_state_cyberattack/

[16] https://www.theregister.com/2021/07/19/hafnium_china_state_security/

[17] https://www.theregister.com/2021/03/03/qualys_ransomware_clop_gang/

[18] https://www.theregister.com/2021/05/26/vmware_vcenter_bug/

[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQJ8Nvr5uDxoUdGZJPYcTwAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[20] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQJ8Nvr5uDxoUdGZJPYcTwAAAEg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[21] https://www.cyber.gov.au/acsc/view-all-content/news/joint-advisory-top-cyber-vulnerabilities

[22] https://whitepapers.theregister.com/



sed quis custodiet ipsos custodes?

Anonymous Coward

But who shall guard the guards themselves?

It's in the name!

TJ1

So, if it has "Secure", "VPN", "net", "IP", or "Microsoft" in the name don't trust it !?

Causes

Mike 137

Looking this dozen up on the CVE, I find:

four failures to sanitize properly;

two failures to parse properly;

one failure to validate properly;

one poor encryption implementation;

one instance of development code left in release;

one instance of open access to script components;

one instance of poor memory management;

one instance of uncontrolled file write.

All these are really quite basic errors that should at least shown up under pre-release testing, and it's interesting (and disturbing) that over half of them are failures to ensure input is valid and legal.

Re: Causes

Headley_Grange

Good work - and maybe not surprising. Releasing good code is expensive. I guess that an analogy is safety critical development (SIL, SW01, DO-178, etc). These standards don't just focus on development, coding and testing, but on the company environment and processes that surround and support them from design concepts to in-service support. It makes SW development in these environments expensive, a bit less fun sometimes, and it makes it much harder for a director to shout "just fucking release it or we'll miss this quarter's numbers".

I don't think we'll ever see security equivalents of these safety standards, partly because of the expense but mainly because of today's expected rapid turnover of product and introduction of new features.

Pascal Monett

So basically programmer lazyness. Apart from a poor encryption implementation (hey, encryption is hard, okay ?), none of the other causes have any sort of valid excuse.

"Apart from a poor encryption implementation..."

Mike 137

Actually, the error was to default the key field to all zeros, so if a user entered key of all zeros it could sometimes allow access. Even I - definitely not a cryprographer - know the default should be random and different every time.

Re: Causes

Julz

Yep, all the sort of things that used to be picked up in testing. I guess you get what you don't pay for.

Fantastic List...

Allan George Dyer

Can they follow up with a list of the the most exploited vulnerabilities abused by friendly states?

Pascal Monett

Define friendly

Allan George Dyer

As defined by Five Eyes infosec agencies, obviously. I'm guessing that is basically the Five Eyes infosec agencies themselves, but who knows? And is there a third category: neutrals? Maybe not, anyone who spies and doesn't share with Five Eyes infosec agencies would go straight into hostile.

I'm also guessing my downvotes are from Five Eyes infosec agencies, hi there, you know where I live.

Julz

Well, given the way the agencies are split into cells, I'm not sure any of them would know what they themselves are doing. Probably got a better chance of discovering what their sister agencies are up to.

Great

Anonymous Coward

Now we have a list of vulnerabilities that the US, UK, and Australia haven't been able to weaponize.

Anonymous Coward

When you see that your FTSE listed employer has bought into almost all of the systems named in the report... And you know they are poor at evergreening patches out. (Head-desk).

Some men rob you with a six-gun -- others with a fountain pen.
-- Woodie Guthrie