The U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has warned organizations that malicious hackers continue to exploit a widely known Pulse Secure VPN vulnerability.

A researcher revealed recently that cybercriminals had started exploiting CVE-2019-11510, a critical vulnerability affecting enterprise VPN products from Pulse Secure, to deliver a piece of ransomware known as Sodinokibi and REvil.

CVE-2019-11510 is an arbitrary file read vulnerability that can be exploited by unauthenticated attackers to obtain private keys and passwords. The attackers can then use these credentials in combination with a remote command injection vulnerability tracked as CVE-2019-11539 to gain access to private VPN networks.

Pulse Secure released patches in April, months before the researchers who discovered the flaws made their findings public, and the company says it has done everything in its power to convince customers to install the patches. Notifications have been sent out via email, product alerts, its community site, a partner portal, and its customer support website.

However, thousands of Pulse Secure VPN endpoints remain unpatched and malicious actors are taking advantage.

“Although Pulse Secure disclosed the vulnerability and provided software patches for the various affected products in April 2019, the Cybersecurity and Infrastructure Security Agency (CISA) continues to observe wide exploitation of CVE-2019-11510,” CISA said.

Bad Packets reported on January 10 that there were still 3,623 vulnerable Pulse Secure VPN servers, including 1,233 in the United States. A similar scan conducted on January 4 showed 3,825 vulnerable servers — only a slight improvement over the past week.

“CISA expects to see continued attacks exploiting unpatched Pulse Secure VPN environments and strongly urges users and administrators to upgrade to the corresponding fixes,” CISA said.

UK-based foreign currency exchange Travelex appears to have been targeted with Sodinokibi ransomware via the Pulse Secure vulnerability. Bad Packets also reported earlier this week that the convenience store chain 7-Eleven also housed some vulnerable VPN servers and the company had not responded to notification attempts.

Pulse Secure told SecurityWeek that the attackers have delivered ransomware “through interactive prompts of the VPN interface to the users attempting to access resources through unpatched, vulnerable Pulse VPN servers.”

Related: NSA: Multiple State-Sponsored APTs Exploiting Enterprise VPN Flaws

Related: APTs Exploiting Enterprise VPN Vulnerabilities, UK Govt Warns

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

%d bloggers like this: