Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-23077PUBLISHED: 2023-02-01Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.
CVE-2023-23078PUBLISHED: 2023-02-01Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
CVE-2023-22287PUBLISHED: 2023-02-01** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.
CVE-2023-23073PUBLISHED: 2023-02-01Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.
CVE-2023-23074PUBLISHED: 2023-02-01Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.
User Rank: Apprentice
4/28/2020 | 12:41:28 PM
The good news is you can reference the list of URLs used in the attack and immediately guard against access to these sites, at least. While updated versions of the trojan may point to other domains, it's a start. Additionally they provide a comprehensive file list that can be used for system scans of malicious files.
Because this SQL injection attack will have been patched against already in a hotfix, the biggest issue currently is the Sophos user base that does not have automatic updates enabled. Opening themselves up to the Asnarok attackers will not only provide access to data for as long as their Sophos installs remain unpatched, they offer a testbed for modifications to the code that could allow bypassing any changes made in the hotfix.