News: 1651572009

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Critical vulnerabilities found in 'millions of Aruba and Avaya switches'

(2022/05/03)


Five critical remote code execution vulnerabilities in millions Aruba and Avaya devices can be exploited by cybercriminals to take full control of network switches commonly used in airports, hospitals, and hotels, according to Armis researchers.

The security firm discovered the bugs, collectively called TLStorm 2.0, and said they stem from insecurities in NanoSSL, a TLS library developed by Mocana that's used in the vulnerable network equipment.

"Some of the vulnerabilities can be triggered with no authentication, no user interaction, and that's why they're so severe," Armis' head of research Barak Hadad told The Register .

[1]

The flaws affect about 10 million devices across HPE's Aruba and Extreme Networks' Avaya switching portfolio, and have severity scores ranging from 9.0 to 9.8 out of 10. If exploited, miscreants can abuse these vulnerabilities to change the behavior of a switch, move laterally to other devices, potentially steal corporate data, and so on.

[2]

[3]

Armis security researchers aren't aware of any in-the-wild exploits, and they worked quickly with both vendors to develop software fixes for the bugs.

TLStorm 2.0 follows the discovery and patching of [4]TLStorm : three critical vulnerabilities said to be in millions of Schneider Electric APC Smart-UPS products. Armis publicly disclosed that vulnerability family [5]last month . In addition to the usual nefarious activities, such as exfiltrating sensitive data from connected devices or deploying malware on the network, exploiting TLStorm on APC UPS machines could result in power outages.

[6]

Besides the ones named so far, Hadad expects to find more vulnerable devices relying on NanoSSL.

"We know that Avaya, Aruba, and APC are vulnerable. And we've been working with them to make sure that their devices will not be vulnerable in the future," he said. "But I'm pretty sure there are other vendors that are vulnerable to this."

Exploiting captive portals

Captive portals are the webpages you usually see the first time you try to connect to a Wi-Fi or wired network at an airport, hotel, hospital, business center, and so on. These may require authentication, payment, or some type of user agreement before providing access to the internet and other services.

When the vulnerable network equipment uses NanoSSL to present a captive portal, criminals can exploit the TLStorm 2.0 vulnerabilities to gain remote code execution, with no need for authentication. And once they control that switch hardware, they can disable the captive portal as well as explore the network for systems to attack, Hadad explained.

[7]Millions of APC Smart-UPS devices vulnerable to TLStorm

[8]PwnedPiper vulns have potential to turn Swisslog's PTS hospital products into Swiss cheese, says Armis

[9]'Tens of millions' of Cisco devices vulnerable to CDPwn flaws: Network segmentation blown apart by security bugs

[10]PwnedPiper vulns have potential to turn Swisslog's PTS hospital products into Swiss cheese, says Armis

One of the Aruba vulnerabilities, CVE-2022-23677, which received a 9.0 out of 10 CVSS score is due to a weakness in NanoSSL that can be exploited via a captive portal. A second Aruba flaw, CVE-2022-23676, is a RADIUS client memory-corruption vulnerability; it is possible to overflow heap memory via this bug to achieve remote-code execution. It received a 9.1 CVSS score. RADIUS is an authentication, authorization, and accounting client-server protocol that can be used to gain access to a network service.

Aruba devices affected by TLStorm 2.0 include:

Aruba 5400R Series

Aruba 3810 Series

Aruba 2920 Series

Aruba 2930F Series

Aruba 2930M Series

Aruba 2530 Series

Aruba 2540 Series

Organizations deploying vulnerable Aruba products should [11]patch impacted devices immediately.

Avaya pre-auth vulns

Meanwhile, the attack surface for the Avaya switches is the web management portal, and none of its three vulnerabilities require any kind of authentication to exploit.

"These are zero-click vulnerabilities that can be exploited over the network with no user interaction," Hadad said.

CVE-2022-29860, which received a CVSS score of 9.8, is a TLS reassembly heap overflow that can lead to remote code execution. It occurs because the process handling POST requests on the webserver doesn't properly validate NanoSSL return values.

[12]

The second critical Avaya bug, CVE-2022-29861, can lead to a stack overflow during HTTP header parsing, which can be exploited to run arbitrary malicious code remotely on the switch. This vuln, which also received a 9.8 CVSS score, is due to an "improper boundary check in the handling of multipart form data combined with a string that is not null-terminated," Armis explained.

And finally the third Avaya vulnerability occurs in the handling of HTTP POST requests. The NanoSSL library doesn't perform an error check, and this leads to an exploitable heap overflow. This one doesn't have a CVE because it occurs in a discontinued Avaya product line. Because it's discontinued, Avaya won't be issuing a patch, and Armis says these devices are still being used.

Avaya devices affected by TLStorm 2.0 include:

ERS3500 Series

ERS3600 Series

ERS4900 Series

ERS5900 Series

Organizations can check Extreme's security advisory [13]page for more information about patches for impacted Avaya devices. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YnFRsBhFrJSgAEXd93OnBgAAAA4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YnFRsBhFrJSgAEXd93OnBgAAAA4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YnFRsBhFrJSgAEXd93OnBgAAAA4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.armis.com/research/tlstorm/

[5] https://www.theregister.com/2022/03/09/tlstorm_apc_ups_critical_zero_days/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YnFRsBhFrJSgAEXd93OnBgAAAA4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/03/09/tlstorm_apc_ups_critical_zero_days/

[8] https://www.theregister.com/2021/08/02/pwnedpiper_swisslog_pts/

[9] https://www.theregister.com/2020/02/05/cisco_cdpwn_flaws/

[10] https://www.theregister.com/2021/08/02/pwnedpiper_swisslog_pts/

[11] https://asp.arubanetworks.com/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YnFRsBhFrJSgAEXd93OnBgAAAA4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://extremeportal.force.com/ExtrSupportHome

[14] https://whitepapers.theregister.com/



Well there's your problem

Pascal Monett

You didn't use Cisco equipment, that can only be backdoored by the NSA.

Re: Well there's your problem

Anonymous Coward

If No Such Agency can backdoor it, then Fairly Universal Criminals Kickin too.

Re: Well there's your problem

EnviableOne

they'll get to C for cisco soon,

they're just finishing the A's APC, Aruba, Avaya ...

Re: Well there's your problem

Yet Another Anonymous coward

If it was Huawei then it could just be poor programming practice - but since this is HPE, the USA's foremost enterprise systems supplier and inheritor of the great engineering of Hewlett Packard - it can only be a deliberate backdoor

Re: Well there's your problem

Paul Crawford

Very true, why bother with Hanlon's razor?

Re: Well there's your problem

VoiceOfTruth

If it was Huawei cue the USA shouting 'Chinese backdoors'.

No longer just a 'consumer' and SOHO problem any more

Mike 137

All this kit is in the $1k to c. $10k bracket, so it's definitely corporate gear. What a pity that it seems to be about the same quality as a typical home router.

Re: No longer just a 'consumer' and SOHO problem any more

Paul Crawford

Probably less, if you have flashed your home one with OpenWRT or similar.

Re: No longer just a 'consumer' and SOHO problem any more

VoiceOfTruth

Let's be honest. Pretty much all hardware and software out there has bugs and holes in it. It's just a matter of time before it is compromised.

You will obey or molten silver will be poured into your ears.