Tag: Research Engineering Manager

Comment from Tenable: Pulse Connect Secure Vulnerability Used to Target Water Agency, Verizon

The trend of attacks against critical infrastructure continues as news broke overnight that Verizon and one of the largest water agencies in the US were reportedly among the group targeted in the hack of Pulse Connect Secure devices. An out-of-band advisory warning that foreign threat actors were targeting previously known vulnerabilities in Pulse Secure was issued on April 20 but the scale of the hack is now starting to become clear. Please find below a comment from Scott Caveza, research engineering manager, Tenable.

“On April 20, Pulse Secure released an out-of-band advisory warning that foreign threat actors were targeting three previously known vulnerabilities (CVE-2019-11510, CVE-2020-8243 and CVE-2020-8260) along with a newly discovered critical authentication bypass zero-day vulnerability (CVE-2021-22893). In the months since, we are now learning about new victims in these attacks as we continue to see attackers leveraging well-known vulnerabilities in their attack chains. CVE-2019-11510, which has been exploited in the wild since details became public in August 2019, was one of the Top 5 vulnerabilities in Tenable’s 2020 Threat Landscape Retrospective report because of its ease of exploitation and widespread exploitation.

“Bad actors are targeting core infrastructure and organisations very aggressively. Patching and securing critical devices must remain a top priority for defenders who should be implementing compensating controls wherever this is not practical. Attackers have had continued success exploiting known vulnerabilities, many with easily identified public proof-of-concept code and patches readily available. Among other things, attackers are targeting networks through VPNs to gain entry into private networks.” — Scott Caveza, research engineering manager, Tenable

Comment from Tenable: Zero-Day Vuln in Pulse Connect Secure Exploited in the Wild

Threat actors are leveraging a zero-day vulnerability in Pulse Connect Secure (PCS), for which there is no immediate patch scheduled for release. Attackers also appear to be leveraging three previously known and patched vulnerabilities in PCS from 2019 and 2020. Please find below a comment from Scott Caveza, Research Engineering Manager, Tenable and a full analysis from Tenable here.

“CVE-2021-22893 is a critical authentication bypass zero-day vulnerability that gives attackers an entry point into Pulse Connect Secure (PCS) SSL VPN appliances. In addition to CVE-2021-22893, attackers also appear to be leveraging three previously known and patched vulnerabilities in PCS from 2019 and 2020: CVE-2019-11510, CVE-2020-8243 and CVE-2020-8260. CVE-2019-11510, which has been exploited in the wild since details became public in August 2019, was one of the Top 5 vulnerabilities in Tenable’s 2020 Threat Landscape Retrospective report because of its ease of exploitation and widespread exploitation.

“Because it is a zero-day and the timetable for the release of a patch is not yet known, CVE-2021-22893 gives attackers a valuable tool to gain entry into a key resource used by many organizations, especially in the wake of the shift to the remote workforce over the last year. Attackers can utilize this flaw to further compromise the PCS device, implant backdoors and compromise credentials. While Pulse Secure has noted that the zero-day has seen limited use in targeted attacks, it’s just a matter of time before a proof-of-concept becomes publicly available, which we anticipate will lead to widespread exploitation, as we observed with CVE-2019-11510.” — Scott Caveza, Research Engineering Manager, Tenable

Comment on unpatched vulnerabilities in SAP applications

A recent advisory from CISA warns that unpatched or misconfigured SAP systems are actively being targeted by threat actors. SAP software is used by organisations to manage critical business functions and often used to store sensitive data. By leveraging known unpatched vulnerabilities, attackers can disrupt critical processes, steal financial or otherwise sensitive data, or deploy malicious code which can lead to a major impact on affected organisations.

Over the last year, we have continued to see reports from U.S. Government agencies warning of the threat of unpatched software and known vulnerabilities being targeted by threat actors.

Despite patches being available for months and even years, attackers are still finding and exploiting unpatched SAP systems. This serves as a reminder to administrators of sensitive data and applications that applying patches, migitations, or workarounds are paramount to thwarting malicious actors looking to exploit well known vulnerabilities.” — Scott Caveza, Research Engineering Manager, Tenable.