New NachoVPN attack uses rogue VPN servers to install malicious updates

Share:

A set of vulnerabilities dubbed “NachoVPN” allows rogue VPN servers to install malicious updates when unpatched Palo Alto and SonicWall SSL-VPN clients connect to them.

AmberWolf security researchers found that threat actors can trick potential targets into connecting their SonicWall NetExtender and Palo Alto Networks GlobalProtect VPN clients to attacker-controlled VPN servers using malicious websites or documents in social engineering or phishing attacks.

Threat actors can use the rogue VPN endpoints to steal the victims’ login credentials, execute arbitrary code with elevated privileges, install malicious software via updates, and launch code-signing forgery or man-in-the-middle attacks by installing malicious root certificates.

SonicWall released patches to address the CVE-2024-29014 NetExtender vulnerability in July, two months after the initial May report, and Palo Alto Networks released security updates today for the CVE-2024-5921 GlobalProtect flaw, seven months after they were informed of the flaw in April and almost one month after AmberWolf published vulnerability details at SANS HackFest Hollywood.

While SonicWall says customers have to install NetExtender Windows 10.2.341 or higher versions to patch the security flaw, Palo Alto Networks says that running the VPN client in FIPS-CC mode can also mitigate potential attacks besides installing GlobalProtect 6.2.6 or later (which fixes the vulnerability).

On Tuesday, AmberWolf disclosed additional details regarding the two vulnerabilities and released an open-source tool dubbed NachoVPN, which simulates rogue VPN servers that can exploit these vulnerabilities.

“The tool is platform-agnostic, capable of identifying different VPN clients and adapting its response based on the specific client connecting to it. It is also extensible, encouraging community contributions and the addition of new vulnerabilities as they are discovered,” AmberWolf explained.

“It currently supports various popular corporate VPN products, such as Cisco AnyConnect, SonicWall NetExtender, Palo Alto GlobalProtect, and Ivanti Connect Secure,” the company added on the tool’s GitHub page.

AmberWolf also released advisories with more technical information regarding the SonicWall NetExtender and Palo Alto Networks GlobalProtect vulnerabilities, as well as attack vector details and recommendations to help defenders protect their networks against potential attacks.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:38 am, Feb 3, 2025
weather icon 1°C
L: -1° | H: 2°
broken clouds
Humidity: 93 %
Pressure: 1025 mb
Wind: 3 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 63%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:35 am
Sunset: 4:53 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
-1° | 2°°C 0 mm 0% 9 mph 95 % 1025 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
6° | 10°°C 0.2 mm 20% 14 mph 96 % 1026 mb 0 mm/h
Wed Feb 05 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 89 % 1045 mb 0 mm/h
Thu Feb 06 9:00 pm
weather icon
2° | 8°°C 0 mm 0% 9 mph 82 % 1045 mb 0 mm/h
Fri Feb 07 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 10 mph 95 % 1038 mb 0 mm/h
Today 3:00 am
weather icon
1° | 3°°C 0 mm 0% 4 mph 93 % 1025 mb 0 mm/h
Today 6:00 am
weather icon
1° | 2°°C 0 mm 0% 4 mph 93 % 1025 mb 0 mm/h
Today 9:00 am
weather icon
3° | 3°°C 0 mm 0% 4 mph 93 % 1025 mb 0 mm/h
Today 12:00 pm
weather icon
6° | 6°°C 0 mm 0% 4 mph 86 % 1025 mb 0 mm/h
Today 3:00 pm
weather icon
7° | 7°°C 0 mm 0% 9 mph 94 % 1023 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 5 mph 95 % 1024 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 5 mph 95 % 1024 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 6 mph 95 % 1024 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,263.32
-7.34%
Ethereum(ETH)
€2,410.22
-21.35%
Tether(USDT)
€0.98
0.08%
XRP(XRP)
€2.05
-27.71%
Solana(SOL)
€182.03
-13.79%
USDC(USDC)
€0.98
0.01%
Dogecoin(DOGE)
€0.222705
-26.67%
Shiba Inu(SHIB)
€0.000013
-26.74%
Pepe(PEPE)
€0.000009
-27.69%
Scroll to Top