HomeSecurityCISA: US Federal Agency Network Breach via GeoServer

CISA: US Federal Agency Network Breach via GeoServer

CISA has published an extensive cybersecurity advisory detailing how malicious actors managed to breach the network of a US federal agency by exploiting CVE-2024-36401, a critical remote code execution vulnerability in GeoServer.

See also: CISA: Two malware exploits Ivanti EPMM vulnerabilities

GeoServer

The incident, which remained undetected for three weeks, highlights significant gaps in vulnerability management and incident preparedness within federal agencies.

The attack began on July 11, 2024, when cybercriminals exploited CVE-2024-36401 in a publicly available installation of GeoServer to gain initial access . This critical vulnerability, disclosed on June 30, 2024, allows unauthorized users to achieve remote code execution via “eval injection” attacks on affected versions of GeoServer. The vulnerability is classified as CWE-95 for “Eval Injection” and was added to the CISA List of Known Exploitable Vulnerabilities (KEV) on July 15, 2024.

Malicious actors showed persistence by exploiting the same vulnerability on a second GeoServer on July 24, 2024, despite the vulnerability having been publicly disclosed 25 days earlier. Between these initial breaches, the attackers conducted extensive reconnaissance using the Burp Suite Burp Scanner to identify vulnerable systems and used publicly available tools, such as the fscan network scanner and linux-exploit-suggester2.pl, for comprehensive network logging.

See also: FTC: Senator calls for investigation into Microsoft's use of RC4

CISA: US Federal Agency Network Breach via GeoServer

After initial access, the malicious actors established persistence through multiple techniques, including deploying China Chopper web shells , creating cron jobs for scheduled command execution, and attempting to escalate privileges using the publicly available dirtycow exploit targeting CVE-2016-5195 . The attackers also installed the RingQ obfuscation tool and used the Stowaway multi-layer proxy tool to establish command and control communications over TCP ports 4441 and 50012 .

The breach escalated as the malicious actors moved laterally from the original GeoServer to a web server and then to a SQL server, uploading web shells and scripts to each compromised system. On the SQL server, they executed extensive discovery commands, such as whoami, systeminfo, tasklist, and netstat -ano to record system information and network connections. The attackers enabled cmdshell for remote code execution and used PowerShell and bitsadmin for payload downloads, demonstrating sophisticated “living-off-the-land” techniques.

The incident went undetected for three weeks until July 31, 2024, when the organization’s endpoint detection and response (EDR) tool detected a suspicious file 1.txt uploaded to the SQL server. This delay in detection occurred despite the fact that the EDR system generated an alert on July 15, 2024, when it detected the Stowaway tool on GeoServer 1, which was not reviewed by the security operations center. The organization’s web server did not have endpoint protection, creating additional blind spots in their security monitoring capabilities.

See also: CISA warns of Android vulnerability exploitation

CISA: US Federal Agency Network Breach via GeoServer

CISA’s analysis revealed three critical lessons from this incident: the vulnerabilities were not promptly addressed despite public disclosure and inclusion on the KEV list, the organization’s incident response plan did not include procedures for engaging third parties and providing the necessary access to security tools, and EDR alerts were not continuously monitored across all systems. The advisory highlights that while July 24, 2024 fell within the KEV patching window, organizations should promptly address known exploited vulnerabilities as part of comprehensive vulnerability management practices.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS