News: 1687389266

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

A (cautionary) tale of two patched bugs, both exploited in the wild

(2023/06/22)


Miscreants are right now exploiting two security bugs for which patches exist, one in a VMware network and applications monitoring tool and the other in some TP-Link routers.

VMware two weeks ago issued a fix for CVE-2023-20887, a critical command-injection vulnerability in Aria Operations for Networks that can be abused to achieve remote code execution.

Meanwhile, TP-Link patched CVE-2023-1389 in mid-March. This is another command-injection vulnerability that can lead to remote code execution. Yesterday, Fortinet researchers warned that a DDoS-as-a-service botnet called Condi is spreading by exploiting still-vulnerable TP-Link Archer AX21 routers.

[1]

So if this sounds like a cautionary tale about bad things happening to unpatched products…it is.

[2]

[3]

The 9.8-out-of-10-severity rated VMware bug, CVE-2023-20887, was [4]disclosed and patched by the virtualization giant on June 7 alongside two other vulnerabilities in Aria Operations for Networks: CVE-2023-20888, an authenticated deserialization vulnerability that received a 9.1 severity score, and CVE-2023-20889, an 8.8-rated information disclosure vulnerability.

Researcher Sina Kheirkhah, working with Trend Micro's Zero Day Initiative [5]found and reported all three security issues to VMware, and last week Kheirkhah uploaded a [6]proof-of-concept exploit for CVE-2023-20887 to GitHub.

[7]

Yesterday GreyNoise CEO Andrew Morris [8]sounded the alarm that the VMware bug had been exploited in the wild. These attacks [9]began June 13 and originated from two IP addresses, according to the company's analysis platform.

Also yesterday, VMware updated its security advisory: "VMware has confirmed that exploitation of CVE-2023-20887 has occurred in the wild."

Condi botnet on the loose

The second bug under active exploit, [10]CVE-2023-1389 , affects TP-Link Archer AX21 firmware versions before 1.1.4. TP-Link disclosed the flaw in April after releasing firmware updates the month earlier.

In its [11]April 27 security advisory for the buggy routers, the vendor including the following disclaimer in all-red letters:

The vulnerability will remain if you do not take all recommended actions. TP-Link cannot bear any responsibility for consequences that could have been avoided by following the recommendations in this statement.

But apparently not everyone took this warning to heart, because on May 1 the US government's Cybersecurity and Infrastructure Security Agency (CISA) [12]added CVE-2023-1389 to its known exploited vulnerabilities catalog.

And now, according to FortiGuard Labs researchers Joie Salvio and Roy Tay, a new Mirai-based botnet called Condi is [13]spreading via TP-Link's CVE-2023-1389.

The botnet is being sold as part of a distributed-denial-of-service (DDoS) package on a Telegram channel called Condi Network that offers DDoS as a service that other criminals can rent, and it also sells the malware source code.

[14]June Patch Tuesday: VMware vuln under attack by Chinese spies, Microsoft kinda meh

[15]Apple squashes kernel bug used by TriangleDB spyware

[16]Guess what happened to this US agency using outdated software?

[17]Third MOVEit bug fixed a day after PoC exploit made public

DDoS attacks, which flood organizations' networks with junk traffic to overwhelm systems and prevent legit users from accessing services, don't require an awful lot of technical know-how in the first place. And these types of [18]DDoS-for-hire services and botnets, of course, further lower the barrier for entry into cybercrime.

Since the end of May, the security shop has seen an "increasing number" of Condi samples, which means that miscreants are actively working to expand the botnet army.

[19]

While the sample that the two researchers analyzed only scanned for CVE-2023-1389, "other Condi botnet samples were also seen exploiting other vulnerabilities to propagate," Salvio and Tay warned. "The publicly available source code for older versions also includes scanners for known vulnerabilities exploited by other Mirai variants." ®

Get our [20]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZJPHYdu7gc10fAeNwLDVlQAAAEM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJPHYdu7gc10fAeNwLDVlQAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZJPHYdu7gc10fAeNwLDVlQAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.vmware.com/security/advisories/VMSA-2023-0012.html

[5] https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-20887/

[6] https://github.com/sinsinology/CVE-2023-20887

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZJPHYdu7gc10fAeNwLDVlQAAAEM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://twitter.com/Andrew___Morris/status/1671159767056932869

[9] https://viz.greynoise.io/tag/vmware-aria-operations-for-networks-rce-attempt?days=30

[10] https://www.fortiguard.com/outbreak-alert/tp-link-archer-ax-21-command-injection

[11] https://www.tp-link.com/us/support/faq/3643/

[12] https://www.cisa.gov/news-events/alerts/2023/05/01/cisa-adds-three-known-exploited-vulnerabilities-catalog

[13] https://www.fortinet.com/blog/threat-research/condi-ddos-botnet-spreads-via-tp-links-cve-2023-1389

[14] https://www.theregister.com/2023/06/13/june_patch_tuesday_vmware_vuln/

[15] https://www.theregister.com/2023/06/21/apple_patches_triangledb_spyware/

[16] https://www.theregister.com/2023/06/19/old_telerik_bug_exploited/

[17] https://www.theregister.com/2023/06/16/third_moveit_bug_fixed/

[18] https://www.theregister.com/2023/05/09/intel_oem_private_keys_leaked/

[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/patches&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZJPHYdu7gc10fAeNwLDVlQAAAEM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[20] https://whitepapers.theregister.com/



razorfishsl

TP-Link again.......

Time to geet some real programmers....

Q: How many DEC repairman does it take to fix a flat?
A: Five; four to hold the car up and one to swap tires.

Q: How long does it take?
A: It's indeterminate.
It will depend upon how many flats they've brought with them.

Q: What happens if you've got TWO flats?
A: They replace your generator.