Skip to content

Finding Juniper SRX and EX devices with runZero

Today, January 12th, 2024, Juniper Networks disclosed a serious vulnerability in Juniper SRX firewalls and EX switches.

The issue, identified as CVE-2024-21591, allows remote attackers to create a denial-of-service (DoS) condition or to execute arbitrary code with root privileges on vulnerable devices.

This vulnerability has a CVSS score of 9.8 out of 10, indicating that this is a critical vulnerability.
According to their disclosure, Juniper Networks is not aware of any active exploitation of this vulnerability.

What is the impact? #

Upon successful exploitation of these vulnerabilities, attackers can execute arbitrary code on the vulnerable system with root privileges. In general, this means that a successful attack would result in complete system compromise.

Are updates or workarounds available? #

Juniper has released a software update to address this vulnerability.
This update available through their support portal and other update distribution mechanisms.

How do I find potentially vulnerable Juniper devices with runZero? #

From the Asset Inventory, use the following query to locate assets that may be running the vulnerable operating system in your network:

hw:"Juniper EX" OR hw:"Juniper SRX"
 
 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

Finding Ivanti Connect Secure and Policy Secure Gateways with runZero

Today, January 10th, 2024, Ivanti disclosed two serious vulnerabilities in the Ivanti Connect Secure and Ivanti Policy Secure products.

The first issue, CVE-2023-46805, allows attackers to bypass authentication controls to access restricted resources without authentication. This vulnerability has a CVSS score of 8.2 out of 10, indicating a high degree of impact.

The second issue, CVE-2024-21887, allows attackers to inject arbitrary commands to be executed on the affected device. Attackers must be authenticated to exploit this vulnerability, but attackers may be able to use the authentication bypass vulnerability above to achieve this. This vulnerability has a CVSS score of 9.1 out of 10, indicating a critical vulnerability.

The vendor reports that there are indications that these vulnerabilities have been exploited in the wild.

What is the impact? #

Upon successful exploitation of these vulnerabilities, attackers can execute arbitrary commands on the vulnerable system. This includes the creation of new users, installation of additional modules or code, and, in general, system compromise.

Are updates or workarounds available? #

Ivanti has released an update to mitigate this issue. Users are urged to update as quickly as possible.

How do I find potentially vulnerable Ivanti devices with runZero? #

From the Services Inventory, use the following query to locate assets running the vulnerable products in your network that expose a web interface and which may need remediation or mitigation:

_asset.protocol:http AND protocol:http AND http.body:"welcome.cgi?p=logo"

Additional fingerprinting research is ongoing, and additional queries will be published as soon as possible.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

The Quest for Yeti

Meet the newest rockstar on our squad: Zeti, the runZero Yeti! 🎉 This sub-zero hero is now our official mascot, and we’re excited to give you the lowdown on how Zeti came to be. Why a Yeti, you ask? Keep reading to find out! 

The Trail to Yeti #

We set out on our epic journey to find the perfect mascot for runZero, with a big hairy goal (yeah, we went there) to find an elusive creature who could capture the personality of runZero. We wanted our mascot to reflect who we are as a company, and also provide a glimpse into the quirkiness, nerdiness, and kindness that permeates life in runZero land. We thought about the roots of our name, the mission that lights a fire in us every day, and what makes our product unique and special.

Our name. With a zero built right into our name, we started thinking about all things ‘below zero’ and ‘arctic’ and the creatures that inhabit these spaces. We’re also a remote-first company, and you can’t get much more remote than the places where temperatures are frequently below zero. The Yeti fits right into our arctic landscape and inhabits remote, farflung locations on the planet.

Our mission. runZero helps people find unknown things in their environments, and reveals the mysteries lurking on their networks so they can take action and improve their security. The Yeti has a mystical allure and knack for staying undetected and off the radar (just like all those unmanaged devices and shadowy subnets on your network), mirroring our mission of unveiling the unknown in networks.

Our product. We believe the runZero Platform is rewriting the story of what a CAASM is and should be. And we aim to bust myths left and right — forget the idea that full network visibility is a mythical beast that demands sacrifices like long setups, pricey gear, and annoying credentials. Heck, we’re even cool with you trying it for free without enduring a sales pitch! We’re all about embracing outlandish ideas and flipping the script. So, a Yeti who emerges from the shadows to the light to blaze a new trail? That’s the Yeti we want to hang with.

After some wild brainstorming (with a few detours involving narwhals and penguins), our Yeti was ready to hit the scene. Enter our amazing illustrator.

Bringing Our Yeti to Life #

We (kind of) love you, Generative AI, but this time we decided to tap into human creativity to help us put a face (and a big furry body) on our Yeti. Shoutout to Kennon James, the genius illustrator behind our Yeti’s makeover. Kennon has worked on all sorts of cool illustration projects over the years, including bringing Marvel superheroes to life, illustrating some popular games you know and love, and creating a pantheon of Cthulhu-inspired artwork. The rabbit hole of his Instagram can be found here — and you can thank us later.

With Kennon’s help, we explored Yetis of all shapes and sizes — short Yetis, tall Yetis, Yetis without necks, Yetis with big shoulders, scary Yetis, muppet-like Yetis, goofy Yetis, serious Yetis… you get the picture. And finally we found our match. This Yeti was a cool character, but also friendly, approachable, and ready to lend a big (really big) hand.

And speaking of hands, it took us a few weeks to realize our Yeti only had four fingers. We aren’t sure what happened to the fifth, but luckily with the magic of the marker, our Yeti now has all five digits. ✋ Check it out for yourself:

Giving Our Yeti a Proper Name #

Next up: picking a name for our Yeti. At our team summit in Austin during the Austin City Limits Festival (because why not?) – we unveiled our Yeti and handed out t-shirts worthy of the festival and the Live Music Capital of the World. Then, we challenged the team to brainstorm the perfect name for our new Yeti.

Our creative geniuses proposed names like Seymour, I.C Moore, and Prints. But the chosen one? Zeti. Rhymes with Yeti, memorable as heck, and totally runZero. And all runZero alums? You’re officially Zetis for life!

To jazz things up, we invited Kennon to join the party and illustrate live with creative input from the crew. Check out the artist at work!

This is just the start, folks! Stay tuned for more Zeti adventures—trust us, you won’t want to miss this! 🚀

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

How to find SysAid Help Desk instances

How to find SysAid Help Desk instances

On the evening of November 8th Microsoft Threat Intelligence announced that they had discovered attacks by a ransomware gang against the SysAid Help Desk software using a zero-day exploit (CVE-2023-47246). These attacks leveraged a directory traversal vulnerability to upload a web shell and deliver the ransomware payload. SysAid has since published an advisory, complete with indicators of compromise, and made a patch available to customers. The Rapid7 blog has additional information about this issue.

What is SysAid Help Desk?

SysAid provides IT help desk and ITSM software as both a cloud service and through an on-premise option.

Are updates available?

SysAid Help Desk has released version 23.3.36 to address this issue.

How do I find potentially vulnerable versions of ActiveMQ with runZero?

SysAid Help Desk services can be found by navigating to the Service Inventory and using the following query:

_asset.protocol:{http} AND protocol:{http} AND (_service.favicon.ico.image.md5:="5f30870725d650d7377a134c74f41cfd" OR last.html.title:"SysAid")

Results from the above query should be triaged to determine if they require patching or vendor intervention.

As always, any prebuilt queries are available from your runZero console. Check out the documentation for other useful inventory queries.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

How to find Apache ActiveMQ instances

How to find Apache ActiveMQ® instances

On October 25th the Apache team announced a vulnerability (CVE-2023-46604) in ActiveMQ that
could lead to unauthenticated remote code execution. Shortly after the issue was disclosed exploits started to appear and the Rapid7 MDR team posted a blog speculating that this vulnerability is being used to
deliver ransomware. The Apache ActiveMQ project scored this as CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H(10.0). 

What is Apache ActiveMQ®?

ApacheMQ® is an open source message broker written in Java that supports AMQP, MQTT, STOMP, and JMS clients. Apache ActiveMQ describes itself as “the most popular open source, multi-protocol, Java-based message broker. It supports industry standard protocols so users get the benefits of client choices across a broad range of languages and platforms.”. ActiveMQ is used for custom application development and is often embedded into commercial product stacks.

Are updates available?

The Apache ActiveMQ team has addressed this issue in versions 5.18.3, 5.17.6, 5.16.7, and 5.15.16, with the appropriate update dependent on which minor version is used.

How do I find potentially vulnerable versions of ActiveMQ with runZero?

Apache ActiveMQ services can be found by navigating to the Asset Inventory and using the following query:

port:61616 OR product:activemq OR protocol:activemq

Results from the above query should be triaged to determine if they require patching or vendor intervention.

As always, any prebuilt queries are available from your runZero console. Check out the documentation for other useful inventory queries.Learn more about runZero

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×