Welcome to the TrustedSec Tech Brief where Director of Security Intelligence Carlos Perez goes over top security news for the week of August 26.
Chapters:
00:00 Intro
01:04 Vault Typhoon Exploitation of Versa Director
02:23 Apache OFBiz Vulnerability
03:12 WPML CMS Plugin
05:33 Rant
News:
POC for CVE-2024-38063 Windows TCP/IP Remote Code Execution Vulnerability
https://github.com/ynwarcs/CVE-2024-3...
Volt Typhoon Exploitation of Versa Director CVE-2024-39717
https://www.cisa.gov/news-events/aler...
In its report released today, Lumen researchers said Volt Typhoon actors use CVE-2024-39717 to drop "VersaMem," a bespoke Web shell for capturing plaintext user credentials on affected systems. The threat actor is also using VersaMem to monitor all inbound requests to the underlying Apache Tomcat Web application server, and to dynamically load in-memory Java modules to it, they said.
Apache OFBiz Vulnerability Exploited CVE-2024-38856
CISA reports active exploitation of the vulnerability after a POC was made available. Apache OFBiz versions through 18.12.14 are impacted, and version 18.12.15 includes a fix.
https://www.cve.org/CVERecord?id=CVE-...
https://github.com/securelayer7/CVE-2...
Vulnerabilities:
RCE in WPML Multilingual CMS Plugin for WordPress
Login for WordPress used by over 1 million sites is susceptible to an Authenticated (Contributor+) Remote Code Execution (RCE) vulnerability through a Twig server-side template injection.
The researcher published a technical blogpost with POC on the bug.
https://sec.stealthcopter.com/wpml-rc...
CVE-ID: CVE-2024-6386
CVSS Score: 9.9
Affected Versions: 4.6.12
POC: Yes
Exploited: No
SonicWall Firewall Vulnerability
CVE-2024-40766
CVSS 9.3
POC: NO
Exploited: NO
The vulnerability impacts SonicWall Gen 5, Gen 6 and Gen 7 firewalls. According to Netlas.io, there are roughly 650,000 internet-exposed instances of SonicWall firewalls.
SonicWall devices have been attacked in the past. https://cloud.google.com/blog/topics/...