Divya@gbhackers.com - 84d
The Cybersecurity and Infrastructure Security Agency (CISA) has issued urgent warnings about multiple actively exploited vulnerabilities affecting popular software and hardware. These flaws impact Zyxel firewalls, CyberPanel, North Grid, and ProjectSend, allowing attackers unauthorized system access and control. Specifically, CyberPanel's CVE-2024-51378, with a critical CVSS score of 10.0, allows authentication bypass and arbitrary command execution, facilitating ransomware deployment. Other vulnerabilities include improper authentication in ProjectSend (CVE-2024-11680), improper XML External Entity restriction in North Grid Proself (CVE-2023-45727), and path traversal in Zyxel firewalls (CVE-2024-11667). These vulnerabilities have been linked to various ransomware campaigns, including PSAUX and Helldown.
Organizations utilizing these products are strongly advised to immediately implement the necessary security updates and mitigations provided by the vendors. The high severity of these vulnerabilities, particularly the perfect score given to CVE-2024-51378, underscores the urgent need for action to prevent exploitation. CISA has added these flaws to its Known Exploited Vulnerabilities catalog and urges federal agencies to remediate them by December 25, 2024. Failure to act promptly leaves organizations vulnerable to significant security breaches and data loss.
References :
- gbhackers.com: CISA Warns of Zyxel Firewalls, CyberPanel, North Grid, & ProjectSend Flaws Exploited in Wild
- securityonline.info: CVE-2024-51378 (CVSS 10): Critical CyberPanel Flaw Under Active Attack, CISA Warns
- The Hacker News: CISA Warns of Active Exploitation of Flaws in Zyxel, ProjectSend, and CyberPanel
- The Hacker News: Information about the Mitel MiCollab zero-day vulnerability.
- Help Net Security: Details on the Mitel MiCollab zero-day vulnerability and PoC exploit.
- www.bleepingcomputer.com: Report on the Mitel MiCollab zero-day vulnerability.
- www.cysecurity.news: CISA Warns of Critical Exploits in ProjectSend, Zyxel, and Proself Systems
- watchTowr Labs: watchTowr : Mitel MiCollab is an application for voice, video, messaging, presence, audio conferencing, mobility and team collaboration. watchTowr publishes vulnerability details for CVE-2024-35286 (SQL Injection), and CVE-2024-41713 (authentication bypass). Additionally they publicly disclose a post-authenticated arbitrary file read vulnerability (unpatched) that Mitel failed to patch within 100 days of reporting. This includes proof of concept.
- www.csoonline.com: Mitel MiCollab VoIP authentication bypass opens new attack paths
- www.mitel.com: Mitel security advisory addressing CVE-2024-41713.
- The Register - Security: Information about the zero-day vulnerability in Mitel MiCollab that allows attackers to access sensitive files.
- securityaffairs.com: U.S. CISA adds CyberPanel flaw to its Known Exploited Vulnerabilities catalog
- gbhackers.com: Report on multiple ICS advisories released by CISA, focusing on vulnerabilities and exploits in AutomationDirect and Planet Technology products.
Classification:
- HashTags: #Vulnerability #Exploit #CISA
- Company: Zyxel, CyberPanel, North Grid, ProjectSend
- Target: Zyxel, CyberPanel, North Grid, ProjectSend users
- Product: Zyxel firewalls, CyberPanel, North Grid, ProjectSend
- Type: Vulnerability
- Severity: Critical
|
|