Threat Advisory

Multiple Nation-State APT Actors Exploit Critical CVEs in Aeronautical Sector

Threat: Vulnerability/Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researchers highlights critical security incidents involving the exploitation of CVE-2022-47966 and CVE-2022-42475. These incidents were carried out by nation-state advanced persistent threat (APT) actors.[/subscribe_to_unlock_form]

Summary:

Researchers highlights critical security incidents involving the exploitation of CVE-2022-47966 and CVE-2022-42475. These incidents were carried out by nation-state advanced persistent threat (APT) actors.[emaillocker id="1283"]

APT actors used CVE-2022-47966 to gain unauthorized access to the organization's web server, which hosted the public-facing application, Zoho ManageEngine ServiceDesk Plus. This vulnerability allows for remote code execution on the ManageEngine application. The exploitation led to root-level access on the web server, the creation of an administrative user account named "Azure," and the ability to download malware, gather network information, and move laterally within the organization's network. It remains unclear whether proprietary information was accessed or exfiltrated due to incomplete data visibility.

Additional APT actors exploited CVE-2022-42475 on the organization's firewall device. CVE-2022-42475 is a heap-based buffer overflow vulnerability in Fortinet's FortiOS.  They gained access by utilizing compromised, disabled administrative account credentials from a previously contracted user. This activity was detected through multiple VPN connections from known-malicious IP addresses.

The recommendations cover managing vulnerabilities, segmenting networks, securing remote access, and other best practices. Immediate actions include patching systems for known exploited vulnerabilities, monitoring remote access software, and removing unnecessary accounts and groups. Tenable offers solutions to identify potential exposures and vulnerabilities, including the mentioned CVEs, through its Tenable One Exposure Management Platform.

Recommendations:

Threat Profile:

References:

The following reports contain further technical details:

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250a

[/emaillocker]
crossmenu