Mitel VoIP equipment was the entry point for a suspected ransomware attack against an undisclosed organization. The vulnerability allowed attackers to execute remote code and gain initial access to the victim’s network.
This was reported by cybersecurity experts from CrowdStrike, who discovered a previously unknown exploit, as well as the techniques used by the attackers to conceal their activity. The attack was carried out via a Mitel VoIP Linux device located on the network perimeter. The vulnerability was assigned the identifier CVE-2022-29499 and was fixed by Mitel in April 2022. It was assigned a critical severity rating of 9.8 out of 10 on the CVSS scale.
Mitel explained: “The vulnerability was discovered in the Mitel Service Appliance component (MiVoice Connect devices — SA 100, SA 400, and Virtual SA). It allows an attacker to execute remote code in the context of this service.”
The exploit used two HTTP GET requests to obtain commands from the attackers’ servers and execute remote code. During the attack, a reverse shell was created, the pdf_import.php web shell was implanted on the device, and then the open-source proxy tool Chisel was downloaded.
To cover their tracks, the malicious binary file was renamed “memdump” and then launched. This allowed the attackers to develop the attack from the VoIP device, but after their activity was detected, they were unable to continue advancing through the network.
The publication of this data coincided with a report by the German company SySS, which identified two vulnerabilities in Mitel 6800/6900 series phones (CVE-2022-29854 and CVE-2022-29855) that could give attackers superuser rights when exploited.
According to CrowdStrike researcher Patrick Bennett, timely software updates are the most important measure for protecting perimeter devices. However, even this does not help if an unknown vulnerability is exploited. Critical resources must be securely isolated from the perimeter: if a border device is compromised, attackers should not be able to gain direct access to key assets in just one step.