SolarWinds Supply Chain Attack Exploits Software Backdoor to Bypass Authentication

A highly sophisticated cyber-attack targets the SolarWinds Orion platform through a compromised supply chain, allowing threat actors to bypass authentication and execute unauthenticated commands.

A highly sophisticated cyber-attack leverages a compromised supply chain to target the SolarWinds Orion platform, allowing advanced persistent threat actors to insert a backdoor into the commercial software. As customers download these Trojan Horse installation packages, attackers gain unauthorized access to their systems. This exceptionally complex intrusion randomizes certain actions, making traditional identification methods like scanning for known indicators of compromise largely ineffective for affected organizations.

The attack specifically affects several versions of the SolarWinds Orion Platform, including 2019.4 HF 5, 2020.2, and 2020.2 HF 1, with additional versions impacted by a related authentication bypass vulnerability known as CVE-2020-10148. The Orion software contains a flaw that allows attackers to bypass API authentication by appending specific parameters, such as WebResource.adx or ScriptResource.adx, to the URI request. This manipulation sets a SkipAuthorization flag, which processes the API request without requiring any user credentials.

Security patches are available for all affected versions of the SolarWinds Orion platform to address this severe vulnerability. Because the attack continues to evolve and presents significant detection challenges, affected organizations face a complex and difficult remediation process. Cybersecurity experts recommend that organizations follow a tiered set of guidance tailored to their specific capabilities and cybersecurity maturity to properly secure their systems.

Read More at the original source →