Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

HP Device Manager Backdoor Lets Attackers Take Over Windows Systems

HP Device Manager Backdoor Lets Attackers Take Over Windows Systems

HP released a security advisory detailing three critical and high severity vulnerabilities in the HP Device Manager that could lead to system takeover.

HP Device Manager is used by admins to remotely manage HP thin clients, devices that use resources from a central server for various tasks.

When chained together, the security flaws discovered by security researcher Nick Bloor could allow attackers to remotely gain SYSTEM privileges on targeted devices running vulnerable versions of HP Device Manager which would allow for full system takeover.

The potential security impact for vulnerable devices also includes “dictionary attacks, unauthorized remote access to resources, and elevation of privilege” according to HP.

Also Read: Cross Border Data Privacy – A Guide For Singapore Businesses

Chainable security flaws

The three HP Device Manager security vulnerabilities are tracked as CVE-2020-6925, CVE-2020-6926, and CVE-2020-6927.

CVE-2020-6925 affects all versions of HP Device Manager and it exposes locally HP Device Manager managed accounts to dictionary attacks because of weak cipher implementation (does not impact customers who use Active Directory authenticated accounts.)

CVE-2020-6926 is a remote method invocation flaw in all versions of HP Device Manager which enables remote attackers to gain unauthorized access to resources.

CVE-2020-6927 is the weakness that may allow attackers to gain SYSTEM privileges via a backdoor database user in the PostgreSQL database (the password used is just a space.)

This last bug does not affect HP “customers who are using an external database (Microsoft SQL Server) and have not installed the integrated Postgres service,” HP explains.

“Essentially remote access was enabled through unauthenticated access to the Java RMI service and an SQL injection vulnerability which allowed Postgres to be reconfigured and direct connections to be established with this backdoor user account,” Bloor told BleepingComputer.

“Combined with some other vulnerabilities this leads to unauthenticated remote command execution as SYSTEM,” Bloor explains.

The list of HP Device Manager vulnerabilities, their severity ratings, and CVEs can be found in the table embedded below.

CVE IDPotential VulnerabilityImpacted VersionCVSS 3.0 Base Score
CVE-2020-6925Weak CipherAll versions of HP Device Manager7.0
CVE-2020-6926Remote Method InvocationAll versions of HP Device Manager9.9
CVE-2020-6927Elevation of PrivilegeHP Device Manager 5.0.0 to 5.0.38.0

Also Read: 10 Practical Benefits Of Managed IT Services

Mitigation measures available

Customers can download HP Device Manager 5.0.4 to secure their systems against potential attacks that could exploit the CVE-2020-6927 elevation of privilege weakness.

HP hasn’t yet published security updates to address the CVE-2020-6925 and CVE-2020-6926 security issues affecting the HP thin client management software.

However, the company provides customers with remediation steps that should at least partially mitigate the security risks. 

The full list of mitigation measures IT admins can take to mitigate the vulnerabilities includes:

  • Limit incoming access to Device Manager ports 1099 and 40002 to trusted IPs or localhost only
  • Remove the dm_postgres account from the Postgres database; or
  • Update the dm_postgres account password within HP Device Manager Configuration Manager; or
  • Within Windows Firewall configuration create an inbound rule to configure the PostgreSQL listening port (40006) for localhost access only. 

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us