News: 1701873907

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

A year on, CISA realizes debunked vuln actually a dud and removes it from must-patch list

(2023/12/06)


A security vulnerability previously added to CISA's Known Exploited Vulnerability catalog (KEV), which was recognized by CVE Numbering Authorities (CNA), and included in reputable threat reports is now being formally rejected by infosec organizations.

CISA [1]removed CVE-2022-28958 from its KEV on December 1, two days after the National Vulnerability Database (NVD) revoked its "vulnerability" status following a months-long review.

The "issue" was thought to be a critical remote code execution (RCE) flaw impacting an end-of-life D-Link router (DIR-816L), carrying a near-maximum severity score of 9.8. It actually had no impact on the systems it targeted.

[2]

VulnCheck CTO Jacob Baines [3]branded it a "fake vulnerability" in December 2022, two months after CISA added it to the KEV, after looking into the proof of concept (PoC) code provided by the original reporter.

[4]

[5]

Baines found the PoC code featured "a glaring error" in that it sent the malicious request to the wrong endpoint, meaning the vulnerability didn't achieve RCE as previously believed.

"After reading the [PoC] code, it's obvious the researcher's proof of concept is useless," Baines said. "It doesn't touch the endpoint where the vulnerable code allegedly resides, and the endpoint it does reach doesn't do anything with the provided parameters."

[6]

Regardless, the original disclosure was enough to convince cybersecurity org MITRE, which maintains the CVE list, the NVD (which maintains a synchronized CVE database), and [7]CISA that the supposed flaw was worthy of attention. Attackers also picked up on the seriousness of it all, with the criminals who operate Moobot [8]adding it to the botnet's capabilities , only to find it didn't work there either.

Baines also noted its operators encoded the exploit incorrectly, so even if the vulnerability was genuine it wouldn't have worked in Moobot's implementation anyway.

"We conclude that [9]CVE-2022-28958 is not a real vulnerability and at-scale exploitation has never occurred," he added. "The vulnerability should not be listed by MITRE, and it should not be in the CISA Known Exploited Vulnerabilities Catalog. We filed a dispute with MITRE and shared our findings with CISA in October 2022."

[10]

When submitting CVE-2022-28958 to the numbering authorities, the original reporter submitted three other vulnerabilities, two of which also received CVEs that Baines claimed probably shouldn't have been assigned in the first place either.

CVE-2022-28955 and CVE-2022-28956 are still considered vulnerabilities and they haven't been rejected, it's important to note. However, Baines said the former "appears to be as-designed functionality with low or no security impact", and the latter "is a real security issue, but a duplicate of four other CVEs."

Internet traffic analysis vendor Greynoise said this week it would stop [11]tracking CVE-2022-28958 (the non-vulnerability), despite a handful of exploits still being attempted.

"The case of CVE-2022-28958 serves as a reminder of the importance of thorough and rigorous vulnerability verification," [12]said Bob Rudis, VP data science, security research, and detection engineering at Greynoise.

"Incorrectly reported [13]vulnerabilities can lead to unnecessary alarm and resource allocation in the cybersecurity community. They can also undermine trust in the reporting and cataloging systems that are crucial for effective vulnerability management." ®

Get our [14]Tech Resources



[1] https://www.cisa.gov/news-events/alerts/2023/12/01/cisa-removes-one-known-exploited-vulnerability-catalog

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZXCouLQvEtNZ7GcdZQSxfgAAABc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://vulncheck.com/blog/moobot-uses-fake-vulnerability

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXCouLQvEtNZ7GcdZQSxfgAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXCouLQvEtNZ7GcdZQSxfgAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXCouLQvEtNZ7GcdZQSxfgAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/12/05/cisa_coldfusion_government/

[8] https://unit42.paloaltonetworks.com/moobot-d-link-devices/

[9] https://nvd.nist.gov/vuln/detail/CVE-2022-28958#VulnChangeHistorySection

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXCouLQvEtNZ7GcdZQSxfgAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://viz.greynoise.io/tag/dlink-dir816-rce-attempt

[12] https://www.greynoise.io/blog/cve-2022-28958-remote-code-execution-vulnerability-dlink-rejected

[13] https://www.theregister.com/2023/08/07/in_brief_security/

[14] https://whitepapers.theregister.com/



Test with all the layers

Dimmer

Working for a bank. Pin testers can’t get access so they request that we add a rule in the firewall to allow them in. Management says we are paying a premium so we need to test everything.

Failing with firewall access, they ask for drop the ACL In the routers and switches.

Failing that, please remove the MS firewall on the servers.

Failing that, we need admin access, and then-

Oh look at all the vulnerabilities we found! We can see your data!

Out comes the report with all the vulnerabilities and we look like we are not doing our job. Fed auditors look at the report and lower the bank rating. Management finally took a hit for stupidity.

Pin testing is when you don’t change any security and they HAVE to prove they can compromise it.

Network assessment is where you give them access.

Know the difference.

Had an auditor as me when we had our last pin test.

“ We get get tested every few seconds, and it is free. Want to see the logs?”

Re: Test with all the layers

Pascal Monett

I believe the terme is pen -testing, because penetration .

I also believe that, if your pen testers can't get through without you deactivating your defenses, you need to find better pen testers.

Re: Test with all the layers

beardman

Oh, the irony... :)))

Re: Test with all the layers

Zola

Yeah, right. Absolutely none of this sounds plausible, assuming the security firm engaged by the bank is legit.

I've worked for investment banks, had client-facing systems I'm responsible for PEN tested multiple times, and none of what you described ever happens (and if anyone did ask for that kind of access they would be run out of business).

Also, the fact you call it "PIN" testing only adds to my suspicion that you don't know what you're talking about.

Re: Test with all the layers

Throatwarbler Mangrove

Maybe their requests were part of the penetration testing: "Are these guys lax enough to comply with all these requests?"

The answer was "yes," so one could argue the bank deserved its falling grade.

genlock, n.:
Why he stays in the bottle.