HomeSecuritySolarWinds warns of attacks targeting Web Help Desk instances

SolarWinds warns of attacks targeting Web Help Desk instances

SolarWinds has warned customers about attacks targeting Web Help Desk (WHD) instances exposed to the Internet and advised them to remove them from publicly accessible infrastructure (possibly to prevent the exploitation of a potential security flaw).

See also: The Russian Nobelium hackers who hacked SolarWinds strike again!

SolarWinds

WHD is a help desk ticket management and IT asset management software designed to help customers automate ticketing and IT asset management tasks.

Customers who cannot immediately remove WHD instances from servers exposed to the Internet are advised to deploy EDR software and monitor them for attack attempts.

SolarWinds is working with the customer to investigate the report, although the company was unable to reproduce the scenario.

See also: Tomiris: The new backdoor that may be linked to SolarWinds hackers

“We received a report from a customer regarding an attempted attack that was not successful,” a SolarWinds spokesperson told BleepingComputer.

“While we are investigating this matter, we have notified other customers of this potential issue out of an abundance of caution. At this point, we have no reason to believe that other customers were affected.”

Web Help Desk Vulnerabilities

Although SolarWinds did not provide details about the tools or techniques used in the attack, there are at least four different security vulnerabilities that an attacker could exploit to target an unpatched WHD instance:

  • Access restriction bypass via referrer spoof – Business logic bypass vulnerability (CVE-2021-32076) – Fixed in WHD 12.7.6
  • HTTP PUT & DELETE methods enabled (CVE-2021-35243) – Fixed in WHD 12.7.7 hotfix
  • Hard-coded credentials allowing arbitrary HSQL query execution (CVE-2021-35232) – Fixed in WHD 12.7.7 hotfix
  • Sensitive Data Disclosure Vulnerability (CVE-2021-35251) – Fixed in WHD version 12.7.8
SolarWinds warns of attacks targeting Web Help Desk instances

See also: SolarWinds hackers: Use iOS zero-day bug to compromise updated iPhones

As detailed in advisory CVE-2021-35251, attackers could exploit unpatched WHD instances to gain access to environmental details about the Web Help Desk installation, which could facilitate the exploitation of the other three security flaws.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS