Neuer NachoVPN-Angriff nutzt betrügerische VPN-Server, um bösartige Updates zu installieren

Teilen:

A set of vulnerabilities dubbed “NachoVPN” allows rogue VPN servers to install malicious updates when unpatched Palo Alto and SonicWall SSL-VPN clients connect to them.

AmberWolf security researchers found that threat actors can trick potential targets into connecting their SonicWall NetExtender and Palo Alto Networks GlobalProtect VPN clients to attacker-controlled VPN servers using malicious websites or documents in social engineering or phishing attacks.

Threat actors can use the rogue VPN endpoints to steal the victims’ login credentials, execute arbitrary code with elevated privileges, install malicious software via updates, and launch code-signing forgery or man-in-the-middle attacks by installing malicious root certificates.

SonicWall released patches to address the CVE-2024-29014 NetExtender vulnerability in July, two months after the initial May report, and Palo Alto Networks released security updates today for the CVE-2024-5921 GlobalProtect flaw, seven months after they were informed of the flaw in April and almost one month after AmberWolf published vulnerability details at SANS HackFest Hollywood.

While SonicWall says customers have to install NetExtender Windows 10.2.341 or higher versions to patch the security flaw, Palo Alto Networks says that running the VPN client in FIPS-CC mode can also mitigate potential attacks besides installing GlobalProtect 6.2.6 or later (which fixes the vulnerability).

On Tuesday, AmberWolf disclosed additional details regarding the two vulnerabilities and released an open-source tool dubbed NachoVPN, which simulates rogue VPN servers that can exploit these vulnerabilities.

“The tool is platform-agnostic, capable of identifying different VPN clients and adapting its response based on the specific client connecting to it. It is also extensible, encouraging community contributions and the addition of new vulnerabilities as they are discovered,” AmberWolf explained.

“It currently supports various popular corporate VPN products, such as Cisco AnyConnect, SonicWall NetExtender, Palo Alto GlobalProtect, and Ivanti Connect Secure,” the company added on the tool’s GitHub page.

AmberWolf also released advisories with more technical information regarding the SonicWall NetExtender and Palo Alto Networks GlobalProtect vulnerabilities, as well as attack vector details and recommendations to help defenders protect their networks against potential attacks.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:30 pm, Juni 16, 2025
Wetter-Symbol 25°C
L: 24° | H: 26°
wenige Wolken
Luftfeuchtigkeit: 47 %
Druck: 1026 mb
Wind: 8 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 15%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:42 am
Sonnenuntergang: 9:19 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
24° | 26°°C 0 mm 0% 6 mph 51 % 1026 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
14° | 27°°C 0 mm 0% 10 mph 65 % 1027 mb 0 mm/h
Mi. Juni 18 10:00 pm
Wetter-Symbol
15° | 28°°C 0 mm 0% 9 mph 73 % 1027 mb 0 mm/h
Do. Juni 19 10:00 pm
Wetter-Symbol
17° | 26°°C 0 mm 0% 11 mph 75 % 1027 mb 0 mm/h
Fr. Juni 20 10:00 pm
Wetter-Symbol
16° | 27°°C 0 mm 0% 11 mph 75 % 1025 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
21° | 24°°C 0 mm 0% 6 mph 51 % 1026 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
17° | 20°°C 0 mm 0% 5 mph 63 % 1027 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 4 mph 65 % 1026 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 5 mph 61 % 1027 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 7 mph 49 % 1026 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 7 mph 31 % 1025 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 8 mph 31 % 1024 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 10 mph 40 % 1024 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€93,248.39
2.27%
Ethereum(ETH)
€2,278.82
3.58%
Fesseln(USDT)
€0.86
0.00%
XRP(XRP)
€2.00
6.88%
Solana(SOL)
€135.96
3.70%
USDC(USDC)
€0.86
-0.01%
Dogecoin(DOGE)
€0.154617
1.79%
Shiba Inu(SHIB)
€0.000010
2.09%
Pepe(PEPE)
€0.000010
1.58%
Nach oben scrollen