APTs Exploiting Multiple VPN Vulnerabilities
Public vulnerabilities in VPN products from several major network vendors are being exploited in ongoing attacks from multiple APT groups. The groups are using bespoke exploits to gain access to target networks through these VPN products.
Summary
Public vulnerabilities in VPN products from several major network vendors are being exploited in ongoing attacks from multiple APT groups. The groups are using bespoke exploits to gain access to target networks through these VPN products.
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Known vulnerabilities in several virtual private network (VPN) products are being actively exploited by advanced persistent threat (APT) groups.
Details
If successful, these groups are able to extract sensitive information, alter network configurations, or take control of connected systems. The vulnerabilities lie in Secure Socket Layer (SSL/TLS) VPN products from Fortinet, Palo Alto Networks, and Pulse. A remote unauthenticated attacker could send specially crafted requests to the affected products in order to obtain arbitrary files, including those containing authentication credentials. These credentials can then be used to access vulnerable VPN systems, at which point the attacker may alter configuration settings or connect to internal systems.
Threat updates
| Date | Update |
|---|---|
| 6 Aug 2020 |
Pulse VPN details posted on ransomware forum
Details on over 900 Pulse Connect Secure VPNs vulnerable to CVE-2019-11510 have bee posted on a number of hacking forums frequented by ransomware operators. The information includes:
All information appears to have been collected between 24/06/2020 and 08/07/2020. |
Remediation advice
Affected organisations are encouraged to review the following security advisories and apply any relevant updates:
- FortiGuard Security Advisory FG-IR-18-384
- FortiGuard Security Advisory FG-IR-18-388
- FortiGuard Security Advisory FG-IR-18-389
- Palo Alto Security Advisory PAN-SA-2019-0020
- Pulse Secure Security Advisory SA44101
Organisations unable to update can apply the below partial mitigation steps.
Remediation steps
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 6 August 2020 10:49 am