Threat Advisory *CRITICAL* – regreSSHion: Critical Vulnerability in OpenSSH (CVE-2024-6387)

Threat Advisory *CRITICAL* – regreSSHion: Critical Vulnerability in OpenSSH (CVE-2024-6387)

Threat Advisory *CRITICAL* – regreSSHion: Critical Vulnerability in OpenSSH (CVE-2024-6387)

DOWNLOAD PDF

Summary

The critical OpenSSH vulnerability impacts almost every Unix-like and Linux system (except OpenBSD), is due to a serious flaw known as “regreSSHion,” (CVE-2024-6387), and exposes Linux environments to remote unauthenticated code execution. The potential impact of this vulnerability is extensive, posing a risk to numerous servers and infrastructure components worldwide.

 

Risk Score

CVE-ID                                       CVSSv3 Score

CVE-2024-6387                   8.1

 

Threat intelligence

PoC available on GitHub

 

Vulnerability Details

“regreSSHion,” exposes Linux environments to remote unauthenticated code execution, potentially leading to root-level access and does not require user interaction. The vulnerability stems from a signal handler race condition in OpenSSH’s server (sshd) affecting versions 8.5p1 to 9.8p1 on glibc-based Linux systems because the syslog() function calls async-signal-unsafe functions like malloc() and free(), resulting in unauthenticated remote code execution with root privileges. This issue arises because sshd’s privileged code is not sandboxed and operates with full privileges. OpenBSD is not affected because its signal alarm (SIGALRM) handler uses syslog_r(), an async-signal-safe version of syslog().

 

This issue is a regression of an older vulnerability (CVE-2006-5051) and can be exploited by attackers through precise timing to manipulate system memory. The complexity of the exploit requires multiple attempts and significant skill, but the potential impact is severe.

 

PoC Exploit

The “regreSSHion” proof of concept exploit on GitHub uses a complex race condition in OpenSSH that requires precise timing and potentially thousands of attempts to succeed. It targets 32-bit systems and has been tested on Debian-based, glibc-based Linux distributions. Key aspects of the exploit include:

  • Timing and Duration: The exploit takes about 10,000 attempts to succeed, approximately 3-4 hours to win the race condition, and 6-8 hours to bypass ASLR and gain remote root shell access.
  • prepare_heap() Function: Sets up memory in a specific way, creating and freeing small chunks, then creating pairs of large and small chunks filled with specific data to create a predictable memory layout.
  • attempt_race_condition() Function: Tries to exploit the race condition by sending a crafted packet to the server, timing the final byte to be sent just before the server times out the connection. This aims to manipulate the server’s memory, allowing the attacker to run code with root permissions.

 

Affected Products

  • OpenSSH version 8.5p1 to 9.7p1
  • Older versions prior to 4.4p1 if unpatched for CVE-2006-5051 and CVE-2008-4109

 

Solution

  • OpenSSH version 9.8p1

 

Recommendations

  • Update to OpenSSH version 9.8p1 or later.
  • If immediate updating is not possible, administrators can set the login timeout to zero (LoginGraceTime=0 in sshd_config) as a temporary mitigation. However, developers warn that this makes the SSH server more susceptible to DDoS attacks.
  • Limit SSH access to necessary IP addresses and networks using firewall rules.
  • Use jump hosts or bastion servers for additional access control.
  • Deploy host-based intrusion prevention tools like fail2ban to monitor and block suspicious SSH activity.
  • Adjust sshd_config settings:
    • Set LoginGraceTime to 0.
    • Reduce MaxStartups to limit unauthenticated connections (e.g., MaxStartups 10:30:100).
    • Set PerSourceMaxStartups to a small number (e.g., 5) to limit connections from a single IP.
  • Implement strict network segmentation using VLANs or network zones to isolate critical systems.
  • Implement multi-factor authentication (MFA) for SSH access.
  • Establish robust logging and monitoring for SSH services with alerts for unusual activity.
  • Consider alternative secure remote access methods that don’t rely on SSH, such as VPN solutions with strong authentication.

 

References

 

June InfraGard Houston Tech CSC CISO Roundtable

June InfraGard Houston Tech CSC CISO Roundtable

Blackswan Cybersecurity CEO, Dr. Mike Saylor, led an interactive discussion at the June InfraGard Houston Tech CSC CISO Roundtable on 6/27.

Dr. Saylor covered how CISOs can manage their attack surface, as well as new threats from AI, and defensive measures against DDoS Attacks and Ransomware.

INFRAGARD HOUSTON JUNE 2024

Threat Advisory *CRITICAL* – regreSSHion: Critical Vulnerability in OpenSSH (CVE-2024-6387)

SolarWinds Ser-U File Transfer Flaw Being Exploited

SolarWinds Ser-U File Transfer Flaw Being Exploited

DOWNLOAD PDF

Summary

A high-severity flaw in SolarWinds Serv-U file transfer software (CVE-2024-28995) is being actively exploited. This is a directory traversal vulnerability that allows attackers to read sensitive files on the host machine.

THREAT ADVISORY

 

CVE-ID                                  CVSSv3 Score

CVE-2024-28995             8.6

 

Threat intelligence

  • Exploitation attempts have been seen in the wild
  • Exploit is trivial
  • Proof of Concept is publicly available

 

Vulnerability Details

The vulnerability is a directory traversal bug affecting all versions of Serv-U software, allowing unauthenticated attackers to read any arbitrary file on the host machine, if they know the file path and the file is not locked.

Rapid7 described the flaw as trivial to exploit, enabling external attackers to access critical files on the host. This vulnerability could be used in “smash-and-grab” attacks where adversaries quickly exfiltrate data from file transfer solutions to extort victims.

Exploits of this vulnerability have been actively observed in the wild, with attempts recorded from China to access files like /etc/passwd. Additionally, GreyNoise reported opportunistic attacks using the flaw against its honeypot servers.  Contrast Security researchers noted that successful exploitation could lead to further attacks by chaining the vulnerability to access credentials and system files, potentially compromising other systems and applications.

 

Affected Products

All versions of the software prior to and including:

  • Serv-U 15.4.2 HF 1
  • Serv-U FTP Server 15.4
  • Serv-U Gateway 15.4
  • Serv-U MFT Server 15.4
  • Serv-U File Server 15.4

 

Solution

  • Serv-U version 15.4.2 HF 2 (15.4.2.157)

 

Recommendations

  • Update to Serv-U version 15.4.2 HF 2 (15.4.2.157) immediately.
  • Monitor network traffic for unusual activity indicative of exploitation attempts.
  • Restrict access to sensitive files and directories.
  • Implement strong access controls and authentication mechanisms.
  • Use intrusion detection systems to detect and respond to potential attacks.
  • Conduct regular security audits and vulnerability assessments on all systems.
  • Ensure all security tools and defenses are up-to-date and properly configured.

 

References

Threat Advisory *CRITICAL* – regreSSHion: Critical Vulnerability in OpenSSH (CVE-2024-6387)

Adobe Commerce and Magento Sites Exposed to CosmicSting Vulnerability

Adobe Commerce and Magento Sites Exposed to CosmicSting Vulnerability

DOWNLOAD PDF

Summary

A recently discovered “CosmicSting” vulnerability affecting Adobe Commerce and Magento websites remains unpatched across the majority of deployed sites, risking catastrophic attacks. Sansec reports that three-quarters of affected websites have not applied the patch, leaving them vulnerable to XML external entity injection (XXE) and remote code execution (RCE).THREAT ADVISORY

CVE-ID CVSSv3 Score
CVE-2024-34102 9.8

Threat intelligence

  • No reported exploits in the wild.
  • Highly exploitable.

Vulnerability Details

The CosmicSting vulnerability (CVE-2024-34102) is a critical flaw that affects Adobe Commerce and Magento platforms, allowing attackers to read sensitive files and potentially execute remote code. This vulnerability is considered the most severe flaw in these platforms over the past two years.

The primary risk stems from XML external entity injection (XXE) and can escalate to remote code execution (RCE) when combined with the iconv bug in Linux.

Sansec statistics show that about 75% of websites using the affected platforms have not applied the patch for CosmicSting, leaving them vulnerable. Attack methods are easily inferred from the patch code, making the vulnerability highly exploitable. CosmicSting has the potential to rank among the most devastating attacks in e-commerce history, comparable to ‘Shoplift’, ‘Ambionics’, and ‘Trojan Order.

Affected Products

  • Adobe Commerce: Versions up to 2.4.7, including 2.4.6-p5, 2.4.5-p7, 2.4.4-p8
  • Adobe Commerce Extended Support: Versions up to 2.4.3-ext-7, 2.4.2-ext-7, 2.4.1-ext-7, 2.4.0-ext-7, 2.3.7-p4-ext-7
  • Magento Open Source: Versions up to 2.4.7, including 2.4.6-p5, 2.4.5-p7, 2.4.4-p8
  • Adobe Commerce Webhooks Plugin: Versions 1.2.0 to 1.4.0

Solution

  • Adobe Commerce: 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9
  • Adobe Commerce Extended Support: 2.4.3-ext-8, 2.4.2-ext-8, 2.4.1-ext-8, 2.4.0-ext-8, 2.3.7-p4-ext-8
  • Magento Open Source: 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9
  • Adobe Commerce Webhooks Plugin: 1.5.0

Recommendations

  • Immediately update to the patched versions listed above.
  • Switch to ‘Report-Only’ mode before upgrading to avoid checkout functionality issues.
  • For those unable to update immediately, check for the vulnerable glibc library using the provided command and upgrade as required.
  • Add the emergency fix code to ‘app/bootstrap.php’ to block most attacks.
  • Regularly monitor and apply security updates to ensure protection against new vulnerabilities.

References

 

Full Lifecycle Cybersecurity Solutions

Full Lifecycle Cybersecurity Solutions

In addition to being named one of the Top 250 MSSPs in the country, Blackswan Cybersecurity also has a history of being committed to the defense of traditionally underserved markets, such as Public Education and Credit Unions. We accomplish this by understanding your business risk, thoroughly assessing your cyber footprint, and developing “right-sized” security programs to fit your specific needs and budget.

FULL LIFECYCLE CYBERSECURITY

DOWNLOAD PDF