Skip to main content

Vulnerabilities exploited in VPN products used worldwide

APTs are exploiting vulnerabilities in several VPN products used worldwide

A small globe being held aloft in a hand

Note

This webpage and attached document were updated to version 2.0 on 8th October 2019.










Additional mitigations

The NCSC strongly recommends that organisations previously targeted by APT actors, or which have detected successful exploitation of their VPNs, carry out the following additional mitigation steps:

  • VPN settings: Check all configuration options for unauthorised changes. This includes the SSH authorized_keys file, new iptables rules and commands set to run on connecting clients. If you have known-good backups of the configuration you can restore then restoring these may be prudent. More information on potential post-exploitation actions is available online.
  • Log analysis and monitoring: Review and continue to monitor logs for the VPN, network traffic and services users connect to through the VPN such as email. Check for connections from uncommon IP addresses, particularly those with successful logins or large data lengths returned. Identify replay attempts using old credentials that have been reset.
  • Wipe the device: If you suspect exploitation has occurred but cannot find specific evidence of changes made, you may wish to factory reset (or wipe) your device. Follow the device manufacturer’s guidance on how to do this.
  • Two-factor authentication: Where possible, enable two-factor authentication for the VPN to defend against password replay attacks.
  • Reduce threat surface: Disable any functionality and ports on the VPN which are not required, or used.


Published

News type

Alert