Pinewood Security Bulletin – Active exploitation of a new NetScaler vulnerability

 

For English, see below.

 

Beschrijving

Citrix heeft bekendgemaakt dat er zich een ernstige kwetsbaarheid bevindt in NetScaler ADC (voorheen Citrix ADC) en NetScaler Gateway (voorheen Citrix Gateway) waarvan aanvallers op dit moment al actief misbruik maken. De kwetsbaarheid (CVE-2025-6543) betreft een “memory overflow” in systemen die geconfigureerd zijn als Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) of als AAA virtual server. Het betreft hier een andere kwetsbaarheid dan de kwetsbaarheid die vorige week werd verholpen. De patches die Citrix vorige week uitbracht, bieden dan ook geen bescherming tegen deze nieuwe kwetsbaarheid.

Aanvallers kunnen de kwetsbaarheid op afstand en zonder authenticatie misbruiken en hiermee een Denial-of-Service (DoS) of “unintended control flow” veroorzaken. Citrix geeft aan dat misbruik kan resulteren in volledige aantasting van de vertrouwelijkheid, integriteit en beschikbaarheid van een kwetsbaar apparaat. Wel geldt dat voor succesvol misbruik aan specifieke vereisten/condities moet zijn voldaan, maar welke dit zijn is niet bekendgemaakt.

Kwetsbare versies

De kwetsbaarheden bevinden zich in onderstaande versies van NetScaler ADC en NetScaler Gateway:

  • NetScaler ADC en NetScaler Gateway 14.1 vóór versie 14.1-47.46
  • NetScaler ADC en NetScaler Gateway 13.1 vóór versie 13.1-59.19
  • NetScaler ADC 13.1-FIPS en NDcPP vóór versie 13.1-37.236-FIPS en NDcPP

Let op: versies 12.1 en 13.0 van NetScaler ADC en NetScaler Gateway zijn wel kwetsbaar, maar ook End-of-Life (EOL) en ontvangen hierdoor geen verdere updates. Klanten wordt dringend geadviseerd om te upgraden naar een ondersteunde versie. NetScaler ADC 12.1-FIPS is echter niet kwetsbaar.

Oplossingen en tijdelijke mitigaties

Citrix heeft nieuwe versies van NetScaler uitgebracht om deze kwetsbaarheden te verhelpen:

  • NetScaler ADC en NetScaler Gateway 14.1-47.46 en latere versies
  • NetScaler ADC en NetScaler Gateway 13.1-59.19 en latere versies
  • NetScaler ADC 13.1-FIPS en 13.1-NDcPP 13.1-37.236 en latere versies

Let op: het installeren van de patches die Citrix op 17 juni 2025 uitbracht, biedt geen bescherming tegen deze nieuwe kwetsbaarheid.

Meer informatie

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met het Pinewood Security Operations Center. Het SOC is bereikbaar via +31 (0)15 750 13 31 en via soc@pinewood.nl.

 

===== ENGLISH =====

Description

Citrix has announced a serious vulnerability in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway), which is currently being actively exploited by attackers. The vulnerability (CVE-2025-6543) is a memory overflow issue in systems configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server. Note that this is a different vulnerability from the one that was addressed last week. Therefore, the patches released by Citrix last week do not protect against this new vulnerability.

 

Attackers can exploit the vulnerability remotely and without authentication, potentially causing a Denial-of-Service (DoS) or “unintended control flow.” Citrix states that exploitation could result in a complete compromise of the confidentiality, integrity, and availability of a vulnerable device. However, successful exploitation requires certain specific conditions to be met, though these have not been disclosed.

Vulnerable versions

The vulnerabilities are present in the following versions of NetScaler ADC and NetScaler Gateway:

  • NetScaler ADC and NetScaler Gateway 14.1 before version 14.1-47.46
  • NetScaler ADC and NetScaler Gateway 13.1 before version 13.1-59.19
  • NetScaler ADC 13.1-FIPS and NDcPP before version 13.1-37.236-FIPS and NDcPP

Note: Versions 12.1 and 13.0 of NetScaler ADC and NetScaler Gateway are also vulnerable but have reached End-of-Life (EOL) and therefore no longer receive updates. Customers are strongly advised to upgrade to a supported version. However, NetScaler ADC 12.1-FIPS is not vulnerable.

Solutions and workarounds

Citrix has released new versions of NetScaler to address these vulnerabilities:

  • NetScaler ADC and NetScaler Gateway 14.1-47.46 and later versions
  • NetScaler ADC and NetScaler Gateway 13.1-59.19 and later versions
  • NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.236 and later versions

Note: Installing the patches released by Citrix on June 17, 2025, does not provide protection against this new vulnerability.

More information

Questions

For questions about this security bulletin, please contact the Pinewood Security Operations Center. The SOC can be contacted at +31 (0)15 750 13 31 and via soc@pinewood.nl.

Arthur van Vliet

Sales Manager

06 – 53 93 88 38

arthur.vanvliet@pinewood.nl

Pinewood Security Bulletin – Critical Vulnerabilities in NetScaler ADC and Gateway (CVE-2025-5349, CVE-2025-5777)

For English, see below.

Beschrijving

Er bevinden zich twee kwetsbaarheden in Citrix NetScaler ADC en NetScaler Gateway. Het gaat om de volgende kwetsbaarheden:

  • CVE-2025-5777: betreft een kwetsbaarheid die een ongeauthenticeerde aanvaller in staat stelt om toegang te verkrijgen tot mogelijk gevoelige informatie in het geheugen, mits het apparaat is geconfigureerd als Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) of als AAA virtual server. Hoewel het type kwetsbaarheid (“out-of-bounds read”) normaal gesproken niet direct kan leiden tot het uitvoeren van willekeurige code, geeft Citrix aan dat misbruik van de kwetsbaarheid kan resulteren in volledige aantasting van vertrouwelijkheid, integriteit en beschikbaarheid.
  • CVE-2025-5349: betreft een kwetsbaarheid in de NetScaler management interface die door een ongeauthenticeerde aanvaller misbruikt kan worden voor het overschrijven van het geheugen (en daarmee het uitvoeren van willekeurige code).

Citrix heeft geen informatie vrijgegeven over het feit of er op dit moment actief misbruik wordt gemaakt van deze kwetsbaarheden. De kwetsbaarheden zijn echter als kritiek geclassificeerd, wat aangeeft dat ze relatief eenvoudig te misbruiken zijn onder de juiste omstandigheden. Daarnaast hebben we in het verleden vergelijkbare kwetsbaarheden gezien die op korte termijn werden misbruikt door diverse actoren.

Kwetsbare versies

De kwetsbaarheden bevinden zich in onderstaande versies van NetScaler ADC en NetScaler Gateway:

  • NetScaler ADC en NetScaler Gateway 14.1 vóór 14.1-43.56
  • NetScaler ADC en NetScaler Gateway 13.1 vóór 13.1-58.32
  • NetScaler ADC 13.1-FIPS vóór 13.1-37.235-FIPS
  • NetScaler ADC 12.1-FIPS vóór 12.1-55.328-FIPS

Let op: versies 12.1 en 13.0 van NetScaler ADC en NetScaler Gateway zijn wel kwetsbaar, maar ook End-of-Life (EOL) en ontvangen hierdoor geen verdere updates. Klanten wordt dringend geadviseerd om te upgraden naar een ondersteunde versie.

Oplossingen en tijdelijke mitigaties

Citrix heeft de kwetsbaarheden verholpen via onderstaande patches en versies:

  • NetScaler ADC en NetScaler Gateway 14.1-43.56 en later
  • NetScaler ADC en NetScaler Gateway 13.1-58.32 en later
  • NetScaler ADC 13.1-FIPS/NDcPP 13.1-37.235 en later
  • NetScaler ADC 12.1-FIPS 12.1-55.328 en later

Daarnaast raadt Citrix aan om, nadat de upgrade is uitgevoerd, onderstaande commando’s uit te voeren om alle bestaande ICA- en PCoIP-sessies op NetScaler-appliances te termineren:

  • kill icaconnection -all
  • kill pcoipConnection -all

Meer informatie

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met het Pinewood Security Operations Center. Het SOC is bereikbaar via +31 (0)15 750 13 31 en via soc@pinewood.nl.

===== ENGLISH =====

Description

Two vulnerabilities have been reported in Citrix NetScaler ADC and NetScaler Gateway. These are two separate vulnerabilities:

  • CVE-2025-5777: is a vulnerability that allows an unauthenticated attacker to gain access to potentially sensitive information in memory, provided the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server. Although the vulnerability type (out-of-bounds read) does not normally lead directly to arbitrary code execution, Citrix classifies the impact as critical and states that exploitation could result in a complete compromise of confidentiality, integrity, and availability.
  • CVE-2025-5349: This is a vulnerability in the NetScaler management interface that can be exploited by an unauthenticated attacker to overwrite memory (and thereby execute arbitrary code).

Citrix has not disclosed whether these vulnerabilities are currently being actively exploited. However, they have been classified as critical, indicating that they are relatively easy to exploit under the right circumstances. Additionally, we have seen similar vulnerabilities in the past that were exploited in the short term by various actors.

Vulnerable versions

The vulnerabilities are present in the following versions of NetScaler ADC and NetScaler Gateway:

  • NetScaler ADC and NetScaler Gateway 14.1 before 14.1-43.56
  • NetScaler ADC and NetScaler Gateway 13.1 before 13.1-58.32
  • NetScaler ADC 13.1-FIPS before 13.1-37.235-FIPS
  • NetScaler ADC 12.1-FIPS before 12.1-55.328-FIPS

Note: Versions 12.1 and 13.0 of NetScaler ADC and NetScaler Gateway are vulnerable but are also End-of-Life (EOL) and therefore do not receive further updates. Customers are strongly advised to upgrade to a supported version.

Solutions and workarounds

Citrix has addressed the vulnerabilities through the following patches and versions:

  • NetScaler ADC and NetScaler Gateway 14.1-43.56 and later
  • NetScaler ADC and NetScaler Gateway 13.1-58.32 and later
  • NetScaler ADC 13.1-FIPS/NDcPP 13.1-37.235 and later
  • NetScaler ADC 12.1-FIPS 12.1-55.328 and later

In addition, Citrix recommends executing the following commands to terminate all existing ICA and PCoIP sessions on NetScaler appliances:

  • kill icaconnection -all
  • kill pcoipConnection -all

More information

Questions

For questions about this security bulletin, please contact the Pinewood Security Operations Center. The SOC can be contacted at +31 (0)15 750 13 31 and via soc@pinewood.nl.

 

Arthur van Vliet

Sales Manager

06 – 53 93 88 38

arthur.vanvliet@pinewood.nl

Pinewood Security Bulletin – Critical Buffer Overflow in Multiple Fortinet Products Exploited in the Wild

Pinewood Security Bulletin – Critical Buffer Overflow in Multiple Fortinet Products Exploited in the Wild

For English, see below.

Beschrijving

Er bevindt zich een stack-based buffer overflow in de webinterface van meerdere Fortinet-producten (CVE-2025-32756). De kwetsbaarheid is aanwezig in de HTTP-component van deze producten. Een niet-geauthenticeerde, externe aanvaller kan via speciaal geprepareerde HTTP-verzoeken willekeurige code uitvoeren op het systeem. Dit kan leiden tot volledige systeemcompromittering. De kwetsbaarheid is aanwezig in de volgende producten:

  • FortiVoice Enterprise
  • FortiMail
  • FortiNDR
  • FortiRecorder
  • FortiCamera

De kwetsbaarheid wordt actief uitgebuit in het wild, met name in FortiVoice-installaties. De aanval vereist geen authenticatie, wat de uitbuiting relatief eenvoudig maakt. De aanvallen omvatten onder andere het inschakelen van debugging, het verzamelen van inloggegevens en het wijzigen van systeeminstellingen.

Kwetsbare versies

De kwetsbaarheden bevinden zich in onderstaande versies van Fortinet-producten:

  • FortiVoice: 6.4.0 t/m 6.4.10, 7.0.0 t/m 7.0.6, 7.2.0
  • FortiMail: 7.0.0 t/m 7.0.8, 7.2.0 t/m 7.2.7, 7.4.0 t/m 7.4.4, 7.6.0 t/m 7.6.2
  • FortiNDR: 1.1 t/m 1.5 (alle versies), 7.0.0 t/m 7.0.6, 7.1 (alle versies), 7.2.0 t/m 7.2.4, 7.4.0 t/m 7.4.7, 7.6.0
  • FortiRecorder: 6.4.0 t/m 6.4.5, 7.0.0 t/m 7.0.5, 7.2.0 t/m 7.2.3
  • FortiCamera: 1.1, 2.0 (alle versies), 2.1.0 t/m 2.1.3

 

Oplossingen en tijdelijke mitigaties

Fortinet heeft de kwetsbaarheden verholpen via onderstaande patches:

  • FortiVoice: 6.4.11, 7.0.7, 7.2.1
  • FortiMail: 7.0.9, 7.2.8, 7.4.5, 7.6.3
  • FortiNDR: 7.0.7, 7.2.5, 7.4.8, 7.6.1
  • FortiRecorder: 6.4.6, 7.0.6, 7.2.4
  • FortiCamera: 2.1.4

Fortinet adviseert organisaties die de patch nog niet kunnen installeren om de toegang tot de beheer webinterface van de getroffen tijdelijk uit te schakelen.

Detectie van mogelijk misbruik

Via een aantal controles is het mogelijk te achterhalen of misbruik van deze kwetsbaarheid heeft plaatsgevonden.

Verkeer vanaf verdachte IP-adressen

Aanvallen zijn gezien vanaf onderstaande IP-adressen. Succesvolle verbindingen vanaf deze IP-adressen richting Fortinet-webinterfaces zijn dan ook verdacht.

  • 198.105.127[.]124 (AS149440 Evoxt Enterprise, GB)
  • 43.228.217[.]173 (AS133905 Layerstack Limited, TW)
  • 43.228.217[.]82 (AS133905 Layerstack Limited, TW)
  • 156.236.76[.]90 (AS149440 Evoxt Enterprise, US)
  • 218.187.69[.]244 (AS7482 Asia Pacific On-Line Service Inc., TW)
  • 218.187.69[.]59 (AS7482 Asia Pacific On-Line Service Inc., TW)

Configuratiewijziging

De debuggingoptie is standaard uitgeschakeld op systemen, maar in de bekende aanvallen schakelen de aanvallers deze optie juist in. Als in de output van het commando ‘diag debug application fcgi’ de regel ‘general to-file ENABLED‘ voorkomt, betekent dit dat debugging is ingeschakeld. Indien de organisatie dit in het verleden niet zelf heeft ingeschakeld, duidt dit op mogelijk misbruik van het systeem.

Nieuwe en gewijzigde bestanden

Bij de bekende aanvallen plaatsen de aanvallers nieuwe bestanden op het systeem en voeren ze wijzigingen door in bestaande bestanden. Het gaat specifiek om onderstaande bestanden:

  • /bin/wpad_ac_helper: malware met MD5-hash 4410352e110f82eabc0bf160bec41d21
  • /bin/busybox: malafide indien de MD5-hash van het bestand gelijk is aan ebce43017d2cb316ea45e08374de7315 of 489821c38f429a21e1ea821f8460e590
  • /data/etc/crontab: nieuwe regel toegevoegd om gevoelige informatie te verkrijgen vanuit fcgi.debug
  • /var/spool/cron/crontabs/root: nieuwe regel toegevoegd om een backup te maken van fcgi.debug
  • /var/spool/.sync: nieuw bestand waarin credentials worden verzameld
  • /etc/pam.d/sshd: nieuwe regel(s) toegevoegd om gebruik te maken van het malafide bestand libfmlogin.so
  • /lib/libfmlogin.so: nieuw bestand (met MD5-hash 364929c45703a84347064e2d5de45bcd), betreft een malafide bibliotheek waarmee gebruikersnamen en wachtwoorden vanuit SSH-logins worden vastgelegd
  • /tmp/.sshdpm: nieuw bestand met daarin de verzamelde SSH-credentials
  • /bin/fmtest: nieuw bestand (met MD5-hash 2c8834a52faee8d87cff7cd09c4fb946) waarmee het netwerk kan worden gescand
  • /etc/httpd.conf: nieuwe regel toegevoegd om de socks5 module te activeren

Meer informatie

Managed Security Services (MSS) klanten

Als u een Pinewood Managed Security Services contract heeft is er geen actie nodig. Pinewood neemt de benodigde maatregelen om uw omgeving te beschermen tegen deze kwetsbaarheden.

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met de Pinewood Servicedesk. De servicedesk is bereikbaar via +31 15 251 36 33 en via support@pinewood.nl.

 

===== ENGLISH =====

Description

A stack-based buffer overflow exists in the web interface of multiple Fortinet products (CVE-2025-32756). The vulnerability is present in the HTTP component of these products. An unauthenticated, remote attacker can execute arbitrary code on the system via specially crafted HTTP requests. This can lead to full system compromise. The vulnerability affects the following products:

  • FortiVoice Enterprise
  • FortiMail
  • FortiNDR
  • FortiRecorder
  • FortiCamera

The vulnerability is actively being exploited in the wild, particularly in FortiVoice installations. The attack does not require authentication, making exploitation relatively easy. The attacks include enabling debugging, collecting login credentials, and modifying system settings.

Vulnerable versions

The vulnerabilities are present in the following versions of Fortinet products:

  • FortiVoice: 6.4.0 through 6.4.10, 7.0.0 through 7.0.6, 7.2.0
  • FortiMail: 7.0.0 through 7.0.8, 7.2.0 through 7.2.7, 7.4.0 through 7.4.4, 7.6.0 through 7.6.2
  • FortiNDR: 1.1 through 1.5 (all versions), 7.0.0 through 7.0.6, 7.1 (all versions), 7.2.0 through 7.2.4, 7.4.0 through 7.4.7, 7.6.0
  • FortiRecorder: 6.4.0 through 6.4.5, 7.0.0 through 7.0.5, 7.2.0 through 7.2.3
  • FortiCamera: 1.1, 2.0 (all versions), 2.1.0 through 2.1.3

Solutions and workarounds

Fortinet has addressed the vulnerabilities through the following patches:

  • FortiVoice: 6.4.11, 7.0.7, 7.2.1
  • FortiMail: 7.0.9, 7.2.8, 7.4.5, 7.6.3
  • FortiNDR: 7.0.7, 7.2.5, 7.4.8, 7.6.1
  • FortiRecorder: 6.4.6, 7.0.6, 7.2.4
  • FortiCamera: 2.1.4

Fortinet advises organizations that cannot yet install the patch to temporarily disable the HTTP/HTTPS administrative interface.

Detection of possible misuse

Several checks can help determine whether this vulnerability has been exploited.

Traffic from Suspicious IP Addresses

Attacks have been observed from the following IP addresses. Successful connections from these IPs to Fortinet web interfaces are considered suspicious:

  • 198.105.127[.]124 (AS149440 Evoxt Enterprise, GB)
  • 43.228.217[.]173 (AS133905 Layerstack Limited, TW)
  • 43.228.217[.]82 (AS133905 Layerstack Limited, TW)
  • 156.236.76[.]90 (AS149440 Evoxt Enterprise, US)
  • 218.187.69[.]244 (AS7482 Asia Pacific On-Line Service Inc., TW)
  • 218.187.69[.]59 (AS7482 Asia Pacific On-Line Service Inc., TW)

Configuration Changes

The debugging option is disabled by default, but in known attacks, attackers enable this option. If the output of the command ‘diag debug application fcgi’ contains the line ‘general to-file ENABLED’, it indicates that debugging is enabled. If the organization did not enable this in the past, it may indicate system compromise.

New and Modified Files

In known attacks, attackers place new files on the system and modify existing ones. Specifically:

  • /bin/wpad_ac_helper: malware with MD5 hash 4410352e110f82eabc0bf160bec41d21
  • /bin/busybox: malicious if MD5 hash is ebce43017d2cb316ea45e08374de7315 or 489821c38f429a21e1ea821f8460e590
  • /data/etc/crontab: new line added to extract sensitive info from fcgi.debug
  • /var/spool/cron/crontabs/root: new line added to back up fcgi.debug
  • /var/spool/.sync: new file collecting credentials
  • /etc/pam.d/sshd: new line(s) added to use malicious file libfmlogin.so
  • /lib/libfmlogin.so: new file (MD5 hash 364929c45703a84347064e2d5de45bcd), a malicious library capturing SSH login credentials
  • /tmp/.sshdpm: new file containing collected SSH credentials
  • /bin/fmtest: new file (MD5 hash 2c8834a52faee8d87cff7cd09c4fb946) used for network scanning
  • /etc/httpd.conf: new line added to activate the socks5 module

More information

Managed Security Services (MSS) customers

If you have a Pinewood Managed Security Services contract, no action is required. Pinewood takes the necessary measures to protect your environment from these vulnerabilities.

Questions

For questions about this security bulletin, please contact the Pinewood Service desk. The service desk can be contacted at +31 15 251 36 33 and via support@pinewood.nl.

Pinewood Security Bulletin – Ivanti EPMM Flaws Exploited in Remote Code Execution Attacks

For English, see below.

Beschrijving

Er bevinden zich twee kwetsbaarheden in Ivanti Endpoint Manager Mobile (EPMM), een oplossing voor mobiel apparaatbeheer (voorheen MobileIron Core). Het betreft de volgende kwetsbaarheden:

  • CVE-2025-4427: door een kwetsbaarheid in de API-component van EPMM kan een ongeauthenticeerde, externe aanvaller toegang krijgen tot API-endpoints die normaal alleen beschikbaar zijn voor geauthenticeerde gebruikers.
  • CVE-2025-4428: een geauthenticeerde aanvaller kan via deze kwetsbaarheid willekeurige code uitvoeren op een kwetsbaar systeem.

Door deze kwetsbaarheden te combineren, kan een aanvaller zonder enige vorm van authenticatie willekeurige code uitvoeren op een kwetsbare EPMM-installatie. De kwetsbaarheden zijn gerelateerd aan open-source bibliotheken waarvan EPMM gebruikmaakt.

De kwetsbaarheden worden momenteel actief uitgebuit in het wild, zij het in beperkte mate. Ivanti heeft bevestigd dat er gerichte aanvallen plaatsvinden waarbij deze kwetsbaarheden worden gecombineerd. Er is geen publiek beschikbare proof-of-concept op het moment van schrijven. Organisaties die API-toegang beperken via Portal ACL’s of een externe Web Application Firewall (WAF) lopen minder risico.

Kwetsbare versies

De kwetsbaarheden bevinden zich in onderstaande versies van Ivanti Endpoint Manager Mobile (EPMM):

  • EPMM versie 11.12.0.4 en eerder
  • EPMM versie 12.3.0.1 en eerder
  • EPMM versie 12.4.0.1 en eerder
  • EPMM versie 12.5.0.0 en eerder

Oplossingen en tijdelijke mitigaties

Ivanti heeft de kwetsbaarheden verholpen via onderstaande patches en nieuwe versies:

  • EPMM versie 11.12.0.5
  • EPMM versie 12.3.0.2
  • EPMM versie 12.4.0.2
  • EPMM versie 12.5.0.1

Ivanti adviseert organisaties die de patch nog niet kunnen installeren om de toegang tot de API te beperken via Portal ACL’s of een externe Web Application Firewall (WAF). Dit verkleint de kans op succesvolle uitbuiting van de kwetsbaarheden.

Meer informatie

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met het Pinewood Security Operations Center. Het SOC is bereikbaar via +31 (0)15 750 13 31 en via soc@pinewood.nl.

===== ENGLISH =====

Description

Two vulnerabilities have been identified in Ivanti Endpoint Manager Mobile (EPMM), a mobile device management solution (formerly MobileIron Core). These vulnerabilities are:

  • CVE-2025-4427: due to a flaw in the API component of EPMM, an unauthenticated, remote attacker can gain access to API endpoints that are normally only available to authenticated users.
  • CVE-2025-4428: an authenticated attacker can exploit this vulnerability to execute arbitrary code on a vulnerable system.

By chaining these vulnerabilities, an attacker can execute arbitrary code on a vulnerable EPMM installation without any form of authentication. The vulnerabilities are related to open-source libraries used by EPMM.

The vulnerabilities are currently being actively exploited in the wild, although on a limited scale. Ivanti has confirmed that targeted attacks are taking place in which these vulnerabilities are combined. At the time of writing, no public proof-of-concept is available. Organizations that restrict API access via Portal ACLs or an external Web Application Firewall (WAF) are at reduced risk.

Vulnerable versions

The vulnerabilities are present in the following versions of Ivanti Endpoint Manager Mobile (EPMM):

  • EPMM version 11.12.0.4 and earlier
  • EPMM version 12.3.0.1 and earlier
  • EPMM version 12.4.0.1 and earlier
  • EPMM version 12.5.0.0 and earlier

Solutions and workarounds

Ivanti has addressed the vulnerabilities through the following patches and new versions:

  • EPMM version 11.12.0.5
  • EPMM version 12.3.0.2
  • EPMM version 12.4.0.2
  • EPMM version 12.5.0.1

Ivanti advises organizations that are unable to install the patch to restrict access to the API via Portal ACLs or an external Web Application Firewall (WAF). This reduces the likelihood of successful exploitation of the vulnerabilities.

More information

Questions

For questions about this security bulletin, please contact the Pinewood Security Operations Center. The SOC can be contacted at +31 (0)15 750 13 31 and via soc@pinewood.nl.

 

Pinewood Security Bulletin –  Sharp Increase in AitM Phishing Attacks on Microsoft Accounts

For English, see below.

Beschrijving

Het Pinewood SOC heeft de laatste dagen een sterke toename waargenomen in phishing-aanvallen die zich richt op inloggegevens voor Microsoft 365. De aanvallen volgen hierbij steeds eenzelfde patroon:

  1. Het slachtoffer ontvangt een e-mail van een (meestal Nederlandse) derde partij wiens account eerder is gecompromitteerd. Deze e-mail bevat veelal de naam van de organisatie en bevat een link die verwijst naar het pad /drive op een steeds wisselend domein (bijvoorbeeld hxxps[:]//<phishdomain>/drive).
  2. Na het klikken op de link komt de gebruiker uit bij een CloudFlare CAPTCHA die uiteindelijk leidt naar een neppe OneDrive-pagina waarop zogenaamd een “Shared file” wordt aangeboden. Zie het screenshot Neppe Onedrive-pagina.png in de bijlagen.
  3. Na het invullen van inloggegevens stuurt de aanvaller het slachtoffer door naar een Actor-in-the-Middle (AitM) phishing-website waarmee de gebruiker uitkomt op de echte Microsoft 365 inlogpagina van de organisatie. De verbinding verloopt echter via de server van de aanvaller, waardoor de sessietokens onderschept worden. Deze phishing-website draait in veel gevallen op een .icu domein met daarin de tekst “securedoc”, zoals bijvoorbeeld hxxps[:]//login[.]securedoc5553[.]icu/. Zie ook het screenshot Phishing-pagina.png in de bijlage.
  4. Na het inloggen via de AitM-website heeft de aanvaller nu de beschikking over de inloggegevens van het slachtoffer, inclusief eventuele tokens die gebruikt worden voor MFA-authenticatie. De aanvaller kan zich hierna bij Microsoft authenticeren op het account van het slachtoffer, zelfs als dit account beveiligd is middels MFA.

Voorkomen van misbruik

Om de kans op een succesvolle aanval te verkleinen is het voor een strakke inrichting van o.a. Conditional Access van groot belang. Denk hierbij aan het volgende:

  • Verklein de standaard “sign-in frequency” van 90 dagen naar een kortere periode.
  • Vereis dat gebruikers zich alleen kunnen aanmelden vanuit managed en compliant devices.
  • Maak gebruik van de “location”-conditie waarmee het mogelijk is om eisen op te leggen m.b.t. de locatie van waaruit de gebruiker inlogt.
  • Maak gebruik van Entra ID Protection Risk policies

Daarnaast kan het voor deze specifieke campagne helpen om eindgebruikers op de hoogte te stellen van hoe ze een aanval kunnen herkennen. Maak hiervoor gebruik van de kenmerken zoals beschreven aan het begin van dit bulletin.

Zie voor meer details over hoe je misbruik kunt voorkomen ook onze eerdere bulletin “Account compromise activity“ (september 2023).

Detectie van mogelijk misbruik

Er bestaan diverse manieren waarop de beschreven aanval is te herkennen. Wees in ieder geval alert op waarschuwingen die Microsoft Defender uitgeeft. De campagne die we nu zien, leidt in veel gevallen tot alarmen zoals:

  • “Risky sign-in after clicking a possible AiTM phishing URL”;
  • “A potentially malicious URL click was detected”; en
  • “Unfamiliar sign-in properties”.

Als u bent aangesloten op het Pinewood SOC wordt op deze meldingen uiteraard actief gemonitord. Daarnaast monitoren we ook op de indicators of compromise van deze phishing-aanvallen vanuit onze verschillende CTI-bronnen.

Het Pinewood SOC heeft verder aanvullende detectiemechanismen waarmee dit type phishing-aanvallen kunnen worden gedetecteerd in een vroeg stadium. Klanten van het Pinewood SOC raden we daarom aan om aan te sluiten op de AitM Monitor indien dit nog niet gebeurd is.

Mitigatieadvies voor Gecompromitteerde Accounts

Op het moment dat een account in handen van een aanvaller valt, is het allereerst van groot belang om dit zo snel mogelijk vast te stellen. De schade is het kleinst als de aanvaller al snel weer de toegang tot een account kwijtraakt. Na het vaststellen van misbruik van een account raden wij aan om standaard een aantal stappen uit te voeren:

  • Schakel het account in eerste instantie uit (disable account) zodat de aanvaller geen gebruik meer kan maken van het account. Verklaar tevens direct alle refresh tokens die aan het account hangen ongeldig zodat de aanvaller ook daar geen gebruik meer van kan maken.
  • Ga ervanuit dat de aanvaller volledige controle heeft over de authenticatie-informatie van de gebruiker. Reset daarom het wachtwoord én controleer de verificatiemethoden (MFA) van de gebruiker. Verwijder alle verificatiemethoden waarover twijfel bestaat.
  • Het is bekend dat aanvallers na een succesvolle inbraak op een account ook regelmatig mail forwarding rules aanmaken zodat zij toegang blijven houden tot de e-mails van een gebruiker, zelfs als zij de controle over het account zelf zijn kwijtgeraakt. Controleer daarom altijd alle mailbox rules en mailbox forwarding rules die op het account zijn geconfigureerd.
  • In sommige gevallen slaagt een aanvaller er zelfs in om een eigen apparaat (device) te registreren op naam van de gebruiker welke vervolgens vertrouwd wordt. Controleer daarom ook of de lijst aan “enrolled devices” valide is.
  • Controleer tot slot alle activiteiten die vanuit het account zijn uitgevoerd vanaf het moment dat dit account in handen van de aanvaller viel. Maak hiervoor gebruik van de uitgebreide audit-functionaliteiten die Microsoft biedt.

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met het Pinewood Security Operations Center. Het SOC is bereikbaar via +31 (0)15 750 13 31 en via soc@pinewood.nl.

===== ENGLISH =====

Description

The Pinewood SOC has observed a significant increase in phishing activity targeting Microsoft 365 credentials in recent days. The attacks follow a consistent pattern:

  1. The victim receives an email from a (usually Dutch) third party whose account has previously been compromised. This email usually contains the name of the organization and includes a link pointing to the path /drive on an ever-changing domain (e.g., hxxps[:]//<phishdomain>/drive).
  2. After clicking on the link, the user ends up with a CloudFlare CAPTCHA that eventually leads to a fake OneDrive page supposedly offering a “Shared file.” See the screenshot Neppe Onedrive-pagina.png in the attachments.
  3. After entering login credentials, the attacker redirects the victim to an Actor-in-the-Middle (AitM) phishing website that takes the user to the organization’s real Microsoft 365 login page. However, the connection goes through the attacker’s server, intercepting the session tokens. In many cases, this phishing website runs on an .icu domain containing the text “securedoc,” such as hxxps[:]//login[.]securedoc5553[.]icu/. See also the screenshot Phishing-pagina.png attached.
  4. After logging in via the AitM website, the attacker now has access to the victim’s login credentials, including any tokens used for MFA authentication. The attacker can then authenticate to Microsoft on the victim’s account, even if this account is secured using MFA.

Preventing Abuse

To reduce the likelihood of a successful attack, it is crucial to have a well-configured Conditional Access setup. Consider the following:

  • Reduce the default “sign-in frequency” from 90 days to a shorter period.
  • Require users to sign in only from managed and compliant devices.
  • Use the “location” condition to impose requirements regarding the location from which the user logs in.
  • Utilize Entra ID Protection Risk policies.

Additionally, for this specific campaign, it may help to inform end-users on how to recognize an attack. Use the characteristics described at the beginning of this bulletin.

For more details on how to prevent abuse, refer to our previous bulletin “Account compromise activity” (September 2023).

Detecting Possible Abuse

There are several ways in which the described attack can be recognized. In any case, be alert to alerts issued by Microsoft Defender. The campaign we’re observing often leads to alerts such as:

  • “Risky sign-in after clicking a possible AiTM phishing URL”;
  • “A potentially malicious URL click was detected”; and
  • “Unfamiliar sign-in properties.”

Of course, if you are a SOC customer, these notifications are actively monitored. In addition, we also monitor for indicators of compromise of these phishing attacks based on our various CTI sources.

The Pinewood SOC has additional controls to detect AitM phishing attacks at an early stage. We therefore recommend that Pinewood SOC customers connect to the AitM Monitor if they have not done so already.

Advice for Mitigation of Account Compromise

If an account falls into the hands of an attacker, it is crucial to identify this as quickly as possible. The damage is minimized if the attacker loses access to the account soon after. Upon detecting account abuse, we recommend performing the following standard steps:

  • Initially disable the account so the attacker can no longer use it. Also, immediately invalidate all refresh tokens associated with the account to prevent the attacker from using them.
  • Assume the attacker has full control over the user’s authentication information. Therefore, reset the user’s password and check the configured verification methods (MFA). Remove any MFA methods that look suspicious.
  • It is known that attackers often create mail forwarding rules after successfully compromising an account to maintain access to the user’s emails, even if they lose control of the account itself. Always check all mailbox rules and mailbox forwarding rules configured on the account.
  • In some cases, an attacker may even register their own device in the user’s name, which is then trusted. Always check if the list of “enrolled devices” is valid.
  • Finally, review all activities performed from the account since it fell into the attacker’s hands. Use the extensive audit functionalities provided by Microsoft for this purpose.

Questions

For questions about this security bulletin, please contact the Pinewood Security Operations Center. The SOC can be contacted at +31 (0)15 750 13 31 and via soc@pinewood.nl.

Pinewood Security Bulletin – Critical Ingress NGINX Vulnerabilities Expose Kubernetes Clusters to RCE

For English, see below.

Beschrijving

Er zijn vijf kritieke kwetsbaarheden ontdekt in de Ingress NGINX Controller voor Kubernetes, gezamenlijk aangeduid als “IngressNightmare”, welke zich specifiek bevinden zich in de admission controller component van de Ingress NGINX Controller. Dit stelt aanvallers in staat om willekeurige code uit te voeren en kwaadaardige NGINX-configuraties te injecteren. De beveiligingslekken bevinden zich specifiek in de NGINX Controller voor Kubernetes en zijn niet van toepassing op reguliere installaties van NGINX. Vooral cloudomgevingen lijken kwetsbaar te zijn.

Misbruik is eenvoudig, vooral omdat de admission controllers vaak toegankelijk zijn via internet zonder authenticatie. De ontdekkers hebben de verschillende stappen beschreven die een aanvaller kan doorlopen om – door het combineren van deze kwetsbaarheden – het uitvoeren van willekeurige code te bereiken. Er zijn nog geen meldingen van actief misbruik, maar de verwachting is dat aanvallers snel zullen proberen hiervan misbruik te maken.

Kwetsbare versies

De kwetsbaarheden bevinden zich in onderstaande versies van de Ingress NGINX Controller:

  • Ingress NGINX Controller versie 1.12.0 en eerder
  • Ingress NGINX Controller versie 1.11.4 en eerder

Oplossingen en tijdelijke mitigatie

De kwetsbaarheden zijn verholpen via onderstaande patches:

  • Ingress NGINX Controller versie 1.12.1
  • Ingress NGINX Controller versie 1.11.5

Gebruikers van self-managed Ingress NGINX Controllers raden wij aan deze patches zo snel mogelijk te installeren om misbruik te voorkomen.

Voor gebruikers van de Ingress NGINX Controllers binnen Azure Kubernetes Services (AKS) geldt dat Microsoft de updates in de komende dagen automatisch zal uitrollen indien gebruikgemaakt wordt van een managed NGINX ingress add-on.

Meer informatie

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met het Pinewood Security Operations Center. Het SOC is bereikbaar via +31 (0)15 750 13 31 en via soc@pinewood.nl.

===== ENGLISH =====

Description

Five critical vulnerabilities have been discovered in the Ingress NGINX Controller for Kubernetes, collectively referred to as “IngressNightmare, specifically in the admission controller component of the Ingress NGINX Controller. The security flaws allow attackers to execute arbitrary code (RCE) and inject malicious NGINX configurations. The vulnerabilities are specific to the NGINX Controller for Kubernetes and do not apply to regular NGINX installations. Cloud environments, in particular, seem to be vulnerable.

Exploitation is relatively easy, especially since the admission controllers are often accessible via the internet without authentication. Researchers have described the various steps an attacker can take to achieve arbitrary code execution by combining these vulnerabilities. There have been no reports of active exploitation yet, but it is expected that attackers will soon attempt to exploit these.

Vulnerable versions

The vulnerabilities are present in the following versions of the Ingress NGINX Controller:

  • Ingress NGINX Controller version 1.12.0 and earlier
  • Ingress NGINX Controller version 1.11.4 and earlier

Solutions and workarounds

The vulnerabilities have been addressed through the following patches:

  • Ingress NGINX Controller version 1.12.1
  • Ingress NGINX Controller version 1.11.5

Users of self-managed Ingress NGINX Controllers are advised to install these patches as soon as possible to prevent exploitation.

For users of Ingress NGINX Controllers running within Azure Kubernetes Services (AKS), Microsoft will automatically roll out the updates in the coming days if a managed NGINX ingress add-on is being used.

More information

Questions

For questions about this security bulletin, please contact the Pinewood Security Operations Center. The SOC can be contacted at +31 (0)15 750 13 31 and via soc@pinewood.nl.

Pinewood Security Bulletin – Active exploitation of vulnerability (CVE-2024-55591) in FortiOS administrative interface

For English, see below.

Beschrijving

Fortinet heeft bekendgemaakt dat er zich een kwetsbaarheid (CVE-2024-55591) bevindt in de Node.js socket module die onderdeel uitmaakt van de beheerinterface op FortiOS- en FortiProxy-gebaseerde systemen. Middels deze kwetsbaarheid kan een aanvaller op afstand en zonder authenticatie vooraf super-admin privileges verkrijgen. Misbruik is mogelijk wanneer de HTTP(S) beheerinterface van een kwetsbaar systeem is opengesteld richting internet en geen IP-restricties zijn toegepast.

Fortinet geeft aan dat deze kwetsbaarheid inmiddels al actief misbruikt is. ArcticWolf heeft een campagne beschreven waarin een onbekende actor sinds november 2024 misbruik lijkt te hebben gemaakt van deze kwetsbaarheid waarbij in sommige gevallen de initiële toegang is misbruikt voor verdere laterale bewegingen in het netwerk van een slachtoffer.

Kwetsbare versies

De kwetsbaarheid bevindt zich in FortiOS 7.0 en FortiProxy 7.0 en 7.2. Overige versies van FortiOS en FortiProxy zijn niet kwetsbaar. Specifiek bevindt de kwetsbaarheid zich onderstaande versies van deze producten:

  • FortiOS 7.0: versies 7.0.0 t/m 7.0.16
  • FortiProxy 7.0: versies 7.0.0 t/m 7.0.19
  • FortiProxy 7.2: versies 7.2.0 t/m 7.2.12

Oplossingen en tijdelijke mitigaties

Fortinet heeft nieuwe versies van FortiOS en FortiProxy uitgebracht om deze kwetsbaarheid te verhelpen. Wij raden aan deze versie zo spoedig mogelijk te installeren:

  • FortiOS 7.0: upgrade naar versie 7.0.17 of nieuwer
  • FortiProxy 7.0: upgrade naar versie 7.0.20 of nieuwer
  • FortiProxy 7.2: upgrade naar versie 7.2.13 of nieuwer

Daarnaast kan misbruik worden voorkomen door de administratieve interface in het geheel niet beschikbaar te stellen via internet of, indien vereist, hierop strikte IP-restricties toe te passen. Het security bulletin van Fortinet beschrijft de configuratie die kan worden toegepast om een dergelijke IP-restrictie op een Fortinet-device toe te passen.

Detectie van mogelijk misbruik

Misbruik kan worden gedetecteerd door in de logging te zoeken naar succesvolle inlogpogingen op het systeem vanuit “jsconsole”, in combinatie met ongebruikelijke IP-adressen. Bij de nu bekende campagne zijn de IP-adressen 1.1.1.1, 127.0.0.1, 2.2.2.2, 8.8.4.4 en 8.8.8.8 zichtbaar als bron-IP.

Daarnaast maakt de aanvaller in sommige gevallen een nieuw administratief account aan met een willekeurige naam wat tevens een indicatie van misbruik is.

Meer informatie

Managed Security Services (MSS) klanten

Als u een Pinewood Managed Security Services contract heeft is er geen actie nodig. Pinewood neemt de benodigde maatregelen om uw omgeving te beschermen tegen deze kwetsbaarheid.

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met de Pinewood Servicedesk. De servicedesk is bereikbaar via +31 15 251 36 33 en via support@pinewood.nl.

===== ENGLISH =====

Description

Fortinet has announced the discovery of a vulnerability (CVE-2024-55591) in the Node.js socket module, which is part of the administrative interface on FortiOS- and FortiProxy-based systems. This vulnerability allows a remote attacker to gain super-admin privileges without prior authentication. Exploitation is possible if the HTTP(S) administrative interface of a vulnerable system is exposed to the internet without applying IP restrictions.

Fortinet has confirmed that this vulnerability has already been actively exploited. ArcticWolf has documented a campaign in which an unknown actor appears to have exploited this vulnerability since November 2024. In some cases, initial access was used for further lateral movement within the victim’s network.

Vulnerable versions

The vulnerability affects FortiOS 7.0 and FortiProxy 7.0 and 7.2. Other versions of FortiOS and FortiProxy are not affected. Specifically, the vulnerability is present in the following versions:

  • FortiOS 7.0: versions 7.0.0 through 7.0.16
  • FortiProxy 7.0: versions 7.0.0 through 7.0.19
  • FortiProxy 7.2: versions 7.2.0 through 7.2.12

Solutions and workarounds

Fortinet has released updated versions of FortiOS and FortiProxy to address this vulnerability. It is strongly recommended to install these updates as soon as possible:

  • FortiOS 7.0: Upgrade to version 7.0.17 or later
  • FortiProxy 7.0: Upgrade to version 7.0.20 or later
  • FortiProxy 7.2: Upgrade to version 7.2.13 or later

To prevent exploitation, ensure that the administrative interface is not accessible via the internet. If this is required, apply strict IP restrictions. Fortinet’s security bulletin provides guidance on configuring IP restrictions on Fortinet devices.

Detection of possible misuse

Exploitation can be detected by checking logs for successful login attempts from “jsconsole,” combined with unusual IP addresses. In the currently known campaign, the following IP addresses have been observed as source IPs: 1.1.1.1, 127.0.0.1, 2.2.2.2, 8.8.4.4, and 8.8.8.8.

Additionally, attackers may create a new administrative account with a random name, which could also indicate misuse.

More information

Managed Security Services (MSS) customers

If you have a Pinewood Managed Security Services contract, no action is required. Pinewood takes the necessary measures to protect your environment from this vulnerability.

Questions

For questions about this security bulletin, please contact the Pinewood Service desk. The service desk can be contacted at +31 15 251 36 33 and via support@pinewood.nl.

Pinewood Security Bulletin –  Critical vulnerability in Ivanti Connect Secure (CVE-2025-0282)

For English, see below.

Beschrijving

Ivanti heeft een ernstige kwetsbaarheid in Connect Secure en Policy Secure bekendgemaakt (CVE-2025-0282) waarmee een niet-geauthenticeerde aanvaller op afstand willekeurige code kan uitvoeren op een kwetsbaar systeem. Volgens Ivanti is deze kwetsbaarheid reeds op kleine schaal misbruikt voor het overnemen van Connect Secure systemen.

Daarnaast heeft Ivanti ook een aanvullende kwetsbaarheid verholpen (CVE-2025-0283) waarmee een geauthenticeerde aanvaller zijn rechten kan verhogen. Hoewel een aanvaller deze tweede kwetsbaarheid ogenschijnlijk in tandem zou kunnen misbruiken met de eerste kwetsbaarheid voor het uitvoeren van willekeurige code met verhoogde rechten, geeft Ivanti aan dat zij nog geen misbruik heeft waargenomen van deze tweede kwetsbaarheid. Mogelijk dat hierin verandering gaat komen nu informatie over deze tweede kwetsbaarheid bekend is geworden.

Kwetsbare versies

Beide kwetsbaarheden bevinden zich in onderstaande Ivanti-producten:

  • Ivanti Connect Secure 22.7: versie 22.7R2.4 en eerder
  • Ivanti Policy Secure 22.7: versie 22.7R1.2 en eerder
  • Ivanti Neurons for ZTA gateways 22.7: versie 22.7R2.3 en eerder

Daarnaast is Ivanti Connect Secure 9.1 wél kwetsbaar voor CVE-2025-0283 maar niet voor CVE-2025-0282. Aangezien deze versie van Connect Secure per 31 december 2024 de End-of-Life (EoL) status heeft bereikt, zal Ivanti voor deze versie géén patch uitbrengen.

Oplossingen en tijdelijke mitigaties

Ivanti raadt aan om allereerst gebruik te maken van de Ivanti Integrity Checker Tool (ICT) om een scan uit te voeren op de integriteit van een systeem:

  • Indien de scan geen bijzonderheden oplevert: ga door met het installeren van updates
  • Indien de scan onverhoopt wél aanwijzingen vindt dat het systeem is gecompromitteerd: voer eerst een fabrieksreset uit om ervoor te zorgen dat schadelijke objecten van het systeem worden verwijderd.

Voor Connect Secure heeft Ivanti versie 22.7R2.5 uitgebracht om deze kwetsbaarheden te verhelpen. Wij raden aan om deze update zo spoedig mogelijk te installeren na het uitvoeren van de ICT scan.

Voor Policy Secure en Neurons for ZTA gateways zal Ivanti in een later stadium een update uitbrengen (gepland op 21 januari 2025) aangezien deze systemen in de regel niet rechtstreeks te benaderen zijn via internet en daarom een kleiner risico lopen.

Detectie van mogelijk misbruik

Ivanti raadt aan om gebruik te maken van de Ivanti Integrity Checker Tool (ICT) om te verifiëren of misbruik van de betreffende kwetsbaarheden heeft plaatsgevonden.

Meer informatie

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met het Pinewood Security Operations Center. Het SOC is bereikbaar via +31 (0)15 750 13 31 en via soc@pinewood.nl.

===== ENGLISH =====

Description

Ivanti has disclosed a critical vulnerability in Connect Secure and Policy Secure (CVE-2025-0282), allowing an unauthenticated attacker to remotely execute arbitrary code on a vulnerable system. According to Ivanti, this vulnerability has already been exploited on a small scale to compromise Connect Secure systems.

Additionally, Ivanti has addressed a second vulnerability (CVE-2025-0283), which allows an authenticated attacker to escalate their privileges. While these two vulnerabilities could potentially be exploited in tandem to execute arbitrary code with elevated privileges, Ivanti has stated that they have not observed any exploitation of the second vulnerability. This could possible change now that information on the second vulnerability has been published.

Vulnerable versions

The following Ivanti products are affected by both vulnerabilities:

  • Ivanti Connect Secure 22.7: version 22.7R2.4 and earlier
  • Ivanti Policy Secure 22.7: version 22.7R1.2 and earlier
  • Ivanti Neurons for ZTA Gateways 22.7: version 22.7R2.3 and earlier

Additionally, Ivanti Connect Secure 9.1 is vulnerable to CVE-2025-0283 but not to CVE-2025-0282. As this version reached End-of-Life (EOL) status on December 31, 2024, Ivanti will not release a patch for it.

Solutions and workarounds

Ivanti strongly recomments using the Ivanti Integrity Checker Tool (ICT) to verify the integrity of your system.

  • If the ICT scan reports no issues: Proceed with installing updates.
  • If the ICT scan detects compromise: Perform a factory reset to remove any malicious elements from the system before proceeding with the update.

For Connect Secure, Ivanti has released version 22.7R2.5, which addresses these vulnerabilities. It is strongly recommended to install this update as soon as possible after performing an ICT scan.

For Policy Secure and Neurons for ZTA Gateways, Ivanti plans to release updates on January 21, 2025, as these systems are generally not exposed directly to the internet and therefore pose a lower risk.

Detection of possible misuse

Ivanti advises using the Ivanti Integrity Checker Tool (ICT) to verify whether exploitation of these vulnerabilities has occurred.

More information

Questions

For questions about this security bulletin, please contact the Pinewood Security Operations Center. The SOC can be contacted at +31 (0)15 750 13 31 and via soc@pinewood.nl.

Pinewood Security Bulletin – Authentication bypass in SonicWall SSL-VPN

For English, see below.

Beschrijving

SonicWall heeft updates uitgebracht om een kwetsbaarheid te verhelpen in de SSL-VPN- en SSH-services op diverse SonicOS-gebaseerde firewalls. Deze kwetsbaarheid (CVE-2024-53704) stelt een kwaadwillende in staat om de authenticatie op een kwetsbaar device te omzeilen. Naast deze kwetsbaarheid verhelpen de updates ook diverse andere – minder ernstige – kwetsbaarheden. Voor één van deze kwetsbaarheden (CVE-2024-53706) geldt dat een aanvaller deze kan inzetten om zijn rechten te verhogen naar root nadat authenticatie heeft plaatsgevonden, wat mogelijk in combinatie met de eerdere kwetsbaarheid is te misbruiken om zonder authenticatie root rechten te verkrijgen.

Kwetsbare versies

De kwetsbaarheid bevindt zich in diverse SonicWall-devices. De onderstaande firewall-versies bevatten de kwetsbaarheid:

  • Gen 7.1 firewalls: SonicOS 7.1.1-7058 en ouder
  • TZ80 firewalls: SonicOS 8.0.0-8035 en ouder

Gen 6.5 en 7.0 firewalls bevatten de kwetsbaarheid niet.

Oplossingen en tijdelijke mitigaties

SonicWall heeft updates uitgebracht om deze kwetsbaarheid te verhelpen. Wij raden dan ook aan de nieuwe versies van SonicOS zo spoedig mogelijk te installeren om misbruik ervan te voorkomen. De kwetsbaarheid is verholpen in onderstaande versies van SonicOS:

  • Gen 7.1 firewalls: SonicOS 7.1.3-7015
  • TZ80 firewalls: SonicOS 8.0.0-8037

Hoewel de Gen 6.5 en 7.0 firewalls deze specifieke kwetsbaarheid niet bevatten, heeft SonicWall ook SonicOS-updates uitgebracht voor deze versies (respectievelijk SonicOS 6.5.5.1-6n en 7.0.1-5165) aangezien er wel andere – minder ernstige – kwetsbaarheden in zijn verholpen. Wij raden aan ook bij gebruik van deze firewalls deze updates te installeren.

Detectie van mogelijk misbruik

Er is geen informatie bekend gemaakt over hoe misbruik van deze kwetsbaarheid gedetecteerd kan worden.

Meer informatie

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met het Pinewood Security Operations Center. Het SOC is bereikbaar via +31 (0)15 750 13 31 en via soc@pinewood.nl.

===== ENGLISH =====

Description

SonicWall has released updates to address a vulnerability in the SSL-VPN and SSH services on various SonicOS-based firewalls. This vulnerability (CVE-2024-53704) allows an attacker to bypass authentication on a vulnerable device. In addition to this issue, the updates also fix several other, less severe vulnerabilities. One of these vulnerabilities (CVE-2024-53706) enables an attacker to escalate privileges to root after authentication, which could potentially be exploited in combination with the previous vulnerability to gain root privileges without prior authentication.

Vulnerable versions

The vulnerability affects various SonicWall devices. The following firewall versions are vulnerable:

  • Gen 7.1 firewalls: SonicOS 7.1.1-7058 and earlier
  • TZ80 firewalls: SonicOS 8.0.0-8035 and earlier

Gen 6.5 and 7.0 firewalls are not affected by this vulnerability.

Solutions and workarounds

SonicWall has released updates to address this vulnerability. It is strongly recommended to install the latest SonicOS versions as soon as possible to prevent exploitation. The vulnerability has been resolved in the following SonicOS versions:

  • Gen 7.1 firewalls: SonicOS 7.1.3-7015
  • TZ80 firewalls: SonicOS 8.0.0-8037

Although Gen 6.5 and 7.0 firewalls are not affected by this specific vulnerability, SonicWall has also released updates for these versions (SonicOS 6.5.5.1-6n and 7.0.1-5165, respectively) to address other, less severe vulnerabilities. We recommend to install these updates as well.

Detection of possible misuse

No information has been disclosed on how to detect exploitation of this vulnerability.

More information

Questions

For questions about this security bulletin, please contact the Pinewood Security Operations Center. The SOC can be contacted at +31 (0)15 750 13 31 and via soc@pinewood.nl.

Pinewood Security Bulletin – Palo Alto urges to restrict access to PAN-OS management interfaces

 

For English, see below.

Beschrijving

Palo Alto heeft een beveiligingsadvies uitgebracht naar aanleiding van een mogelijke ernstige kwetsbaarheid die zich in de managementinterface van PAN-OS-devices bevindt en waar op dit moment nog weinig details over bekend zijn. Om de kans op misbruik van deze kwetsbaarheid te verkleinen, raadt Palo Alto gebruikers aan om de PAN-OS managementinterface alleen bereikbaar te maken voor vertrouwde en interne IP-adressen.

Volgens Palo Alto vindt er op dit moment nog geen actief misbruik van de kwetsbaarheid plaats.

Kwetsbare versies

Het is op dit moment nog niet duidelijk welke versies van PAN-OS kwetsbaar zijn.

Oplossingen en tijdelijke mitigaties

Als een best practice, zou de managementinterface van PAN-OS-devices niet breed opengesteld moeten zijn richting het internet. Toegang tot de interface zou in principe alleen moeten worden toegestaan vanaf interne IP-adressen.

Palo Alto heeft een overzicht van publiek bereikbare PAN-OS-devices van een organisatie opgenomen in het support-portal. Wij raden dan ook aan om in te loggen op https://support.paloaltonetworks.com/ en vervolgens te kijken of er devices voorzien zijn van de tag PAN-SA-2024-0015 via Products → Assets → All Assets → Remediation Required.

Palo Alto heeft daarnaast specifieke stappen voor het afschermen van de management interface beschreven in een blogartikel. Hierin raadt men aan om:

  • De managementinterface te koppelen aan een gescheiden management VLAN.
  • Gebruik te maken van jump servers om toegang tot de managementinterface te kunnen krijgen.
  • Alleen specifieke beheer IP-adressen toegang te verlenen tot de managementinterface.
  • Alleen ICMP/Ping-, SSH- en HTTPS-verkeer open te stellen op de managementinterface.
  • Het standaard generieke admin-account te verwijderen en te vervangen door losse beheeraccounts voor elke beheerder die toegang moet hebben tot het device (met alleen de rollen toegekend die nodig zijn voor het uitvoeren van beheerwerkzaamheden).

Detectie van mogelijk misbruik

Er zijn nog geen indicaties van mogelijk misbruik bekend.

Meer informatie

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met het Pinewood Security Operations Center. Het SOC is bereikbaar via +31 (0)15 750 13 31 en via soc@pinewood.nl.

===== ENGLISH =====

Description

Palo Alto has issued a security advisory because of a potentially severe vulnerability within the management interface of PAN-OS devices, of which few details are currently known. To reduce the risk of exploitation, Palo Alto recommends making the PAN-OS management interface accessible only from trusted and internal IP addresses.

According to Palo Alto, there is currently no active exploitation of the vulnerability.

Vulnerable versions

It is not yet clear which versions of PAN-OS are affected.

Solutions and workarounds

As a best practice, the management interface of PAN-OS devices should not be broadly accessible from the internet. Access to the interface should, in principle, only be allowed from internal IP addresses.

Palo Alto has included an overview of publicly accessible PAN-OS-devices belonging to an organization in its support portal. Users are advised to log in at https://support.paloaltonetworks.com/ and check whether any devices are tagged with PAN-SA-2024-0015 via Products Assets All Assets Remediation Required.

Additionally, Palo Alto has outlined specific steps to secure the management interface in a blog post. These include:

  • Connecting the management interface to a separate management VLAN.
  • Using jump servers to access the management interface.
  • Granting access to the management interface only to specific administrative IP addresses.
  • Exposing only ICMP/Ping, SSH, and HTTPS traffic on the management interface.
  • Removing the default generic admin account and replacing it with individual administrative accounts for each administrator who requires access (assigning only the roles necessary for administrative tasks).

Detection of possible misuse

No indications of potential exploitation are currently known.

More information

Questions

For questions about this security bulletin, please contact the Pinewood Security Operations Center. The SOC can be contacted at +31 (0)15 750 13 31 and via soc@pinewood.nl.