THREAT LEVEL - HIGH

27-09-2024

New Critical Unauthenticated RCE Flaw Impacting all GNU/Linux systems

Threat Level Description

IthacaLabs has maintained the Threat Level: High – An attack is highly likely. Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.

Description

A critical unauthenticated Remote Code Execution (RCE) in CUPS (Common UNIX Printing System), which impacts Linux and UNIX-based systems, has been identified.

The flaw allows unauthenticated attackers to remotely execute code by exploiting the cups-browsed service on UDP port 631, enabling them to hijack devices, gain control of affected systems, or may disrupt services.

The vulnerability requires no prior authentication and can be triggered when a user initiates a print job, with attackers also able to exploit it through LAN-based spoofing of mDNS/DNS-SD advertisements.

This issue affects a wide range of systems, including multiple Linux distributions, BSD, Oracle Solaris, and other UNIX-based platforms like ChromeOS.

CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177 have been assigned to these CUPS issues, along with several other exploitable bugs.

Red Hat has acknowledged the seriousness of the flaw and is collaborating with OpenPrinting to develop a fix, which will be included in future releases.

Affected Products

  • All Linux distributions that use cups-browsed.
  • UNIX-based systems, including ChromeOS, Oracle Solaris, and BSD.

Recommendation(s)

You should immediately disable the cups-browsed service and block access to UDP port 631 to mitigate RCE risks, monitor security updates for patches, and limit network exposure by disabling unused printing services until updates are applied.

You should understand the importance of security updates, and the urgency with which they should be applied, no matter how large or small your organization is. It is very important to apply an efficient patch management solution and always have enabled an active event security logging and practice event monitoring. To protect the valuable assets of your business and be compliant with the relevant industry regulations requires a comprehensive approach to the management of risk, including Penetration Testing at least annually and upon significant changes.

References:

SIGN UP

Get the latest Threat Alerts in your inbox.