Hackers exploited a zero-day on Linux-based Mitel MiVoice VOIP appliances for initial access in a suspected ransomware attack.
Mitel VOIP devices are used by critical organizations in various sectors for telephony services and were recently exploited by threat actors for high-volume DDoS amplification attacks.
According to new findings by CrowdStrike, a zero-day remote code execution flaw, tracked as CVE-2022-29499 (with a severity score: 9.8 – critical), was used to gain initial access to the network.
Although the attack was stopped, CrowdStrike believes the zero-day was used as part of a ransomware attack.
The vulnerability lies in the Mitel Service Appliance component of MiVoice Connect, used in SA 100, SA 400, and Virtual SA, allowing a malicious actor to perform remote code execution (RCE) in the context of the Service Appliance.
The problem is caused by insufficient data validation for a diagnostic script, allowing remote unauthenticated attackers to inject commands using specially crafted requests.
The exploit involves two GET requests, which are used to retrieve a specific resource from a server — to trigger remote code execution by fetching rogue commands from the attacker-controlled infrastructure.
The threat actors used the vulnerability to create a reverse shell by leveraging FIFO pipes on the targeted Mitel device, sending outbound requests from within the compromised network.
After establishing the reverse shell, the intruder created a web shell (pdf_import.php) and downloaded a reverse proxy tool called “Chisel,” to reduce the chances of detection while moving laterally in the network.
The threat actor also tried to delete all files in the compromised devices using the “dd” overwrite command. However, the analysts could retrieve evidence from the /tmp partition and recover HTTP access logs.
An official patch has not been released but Mitel addressed it on April 19, 2022, by releasing a remediation script for MiVoice Connect versions 19.2 SP3 and earlier and R14.x and earlier.
According to security researcher Kevin Beaumont, there are over 21,500 publicly accessible Mitel devices online, with the majority located in the United States, followed by the United Kingdom, Canada, France, and Australia.
As at least one ransomware operation is believed to be exploiting this vulnerability, it is strongly recommended that admins must apply the mitigations at the earliest.

















Comments