Skip to main content

APTs Exploiting Multiple VPN Vulnerabilities

Public vulnerabilities in VPN products from several major network vendors are being exploited in ongoing attacks from multiple APT groups. The groups are using bespoke exploits to gain access to target networks through these VPN products.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Public vulnerabilities in VPN products from several major network vendors are being exploited in ongoing attacks from multiple APT groups. The groups are using bespoke exploits to gain access to target networks through these VPN products.


Threat details

Introduction

Known vulnerabilities in several virtual private network (VPN) products are being actively exploited by advanced persistent threat (APT) groups.


Details

If successful, these groups are able to extract sensitive information, alter network configurations, or take control of connected systems. The vulnerabilities lie in Secure Socket Layer (SSL/TLS) VPN products from Fortinet, Palo Alto Networks, and Pulse. A remote unauthenticated attacker could send specially crafted requests to the affected products in order to obtain arbitrary files, including those containing authentication credentials. These credentials can then be used to access vulnerable VPN systems, at which point the attacker may alter configuration settings or connect to internal systems.


Threat updates

Date Update
6 Aug 2020 Pulse VPN details posted on ransomware forum

Details on over 900 Pulse Connect Secure VPNs vulnerable to CVE-2019-11510 have bee posted on a number of hacking forums frequented by ransomware operators. The information includes:

  • unique device IP addresses
  • VPN firmware versions
  • administration account details
  • local user lists
  • hashed local user passwords
  • last login information, including username and password (in cleartext)
  • SSH keys
  • session cookies

All information appears to have been collected between 24/06/2020 and 08/07/2020.


Remediation advice

Affected organisations are encouraged to review the following security advisories and apply any relevant updates:

Organisations unable to update can apply the below partial mitigation steps.


Remediation steps

Type Step
Action

Update VPN account credentials and implement a suitable multi-factor authentication solution


Guidance

Restrict administrative access to dedicated internal management networks. Prevent administrative access to any public-facing VPN applications.


Action

Re-issue VPN server keys and certificates.


Guidance

Enable suitable VPN logging; including network metadata, configuration changes, and access attempts. Ensure these logs are reviewed periodically.


Aware

Ensure public-facing VPN applications use TLS 1.2 or newer.





CVE Vulnerabilities

Last edited: 6 August 2020 10:49 am