Summary:
A critical remote code execution vulnerability, tracked as CVE-2023-43177, was discovered in the CrushFTP enterprise suite by researchers. The flaw allowed unauthenticated attackers to compromise servers, access files, execute code, and retrieve plaintext passwords. The vulnerability exploited an unauthenticated mass-assignment vulnerability, manipulating AS2 header parsing to control user session properties. Attackers could send payloads to specific ports, overwriting session data and achieving root-level remote code execution. The exploit demonstrated the exploitation process, showcasing how attackers could overwrite user info, gain admin access, and execute arbitrary Java code. Approximately 10,000 public facing CrushFTP instances were identified, posing a significant attack surface. Despite patches, converge warned of potential threats, as the security patch had been reverse-engineered, and adversaries developed proofs of concept. To mitigate risks, users were advised to update CrushFTP, enable automatic security patch updates, change the password algorithm to Argon, audit for unauthorized users, activate Limited Server mode, and implement additional security measures such as using limited privilege accounts, deploying reverse proxies, and setting firewall rules. Immediate implementation of these measures was crucial, as the publicly disclosed exploit details were likely to be exploited in opportunistic attacks.[/subscribe_to_unlock_form]
Summary:
A critical remote code execution vulnerability, tracked as CVE-2023-43177, was discovered in the CrushFTP enterprise suite by researchers. The flaw allowed unauthenticated attackers to compromise servers, access files, execute code, and retrieve plaintext passwords. The vulnerability exploited an unauthenticated mass-assignment vulnerability, manipulating AS2 header parsing to control user session properties. Attackers could send payloads to specific ports, overwriting session data and achieving root-level remote code execution. The exploit demonstrated the exploitation process, showcasing how attackers could overwrite user info, gain admin access, and execute arbitrary Java code. Approximately 10,000 public facing CrushFTP instances were identified, posing a significant attack surface. Despite patches, converge warned of potential threats, as the security patch had been reverse-engineered, and adversaries developed proofs of concept. To mitigate risks, users were advised to update CrushFTP, enable automatic security patch updates, change the password algorithm to Argon, audit for unauthorized users, activate Limited Server mode, and implement additional security measures such as using limited privilege accounts, deploying reverse proxies, and setting firewall rules. Immediate implementation of these measures was crucial, as the publicly disclosed exploit details were likely to be exploited in opportunistic attacks.[emaillocker id="1283"]
Recommendations:
References:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/exploit-for-crushftp-rce-chain-released-patch-now/
[/emaillocker]