cPanel & WHM Vulnerability

cPanel & WHM Vulnerability

Digital Defense, Inc. is disclosing a vulnerability identified in cPanel & WHM discovered by our Vulnerability Research Team (VRT).  The engineers at cPanel & WHM are to be commended for their prompt response to the identified flaw and their team’s work with VRT to provide prompt fixes for this cyber security issue.

cPanel & WHM has provided a patch for the vulnerability identified on the application. The patch is available for download via Software Update.

Digital Defense will not be providing an automated check for this flaw as validation and exploit techniques require specific conditions to be met that cannot be automated.

Details of the vulnerabilities are as follows:

Summary:

DDI-VRT-2020-04 – cPanel & WHM 2FA bypass (CVE-2020-27641)

Details

Vulnerability:

cPanel & WHM MFA Bypass

Impact:

The MFA bypass can be leveraged by an attacker to circumvent MFA protections on accounts for which the attacker has valid credentials.

Application/Version Affected:

cPanel & WHM versions prior to 11.92.0.2, 11.90.0.17, and 11.86.0.32

Details:

When MFA is enabled, a user who has the feature enabled may submit as many attempts for the MFA key as they would like without any lockout or delays to prevent a brute force attack. This results in a scenario where an attacker with knowledge of valid credentials could bypass MFA protections on an account within a matter of hours. Our testing has demonstrated that with finer tuning of attack it can be accomplished in minutes.

The post cPanel & WHM Vulnerability appeared first on Digital Defense, Inc..

*** This is a Security Bloggers Network syndicated blog from Digital Defense, Inc. authored by Digital Defense Inc.. Read the original post at: https://www.digitaldefense.com/resources/vulnerability-research/cpanel-and-whm-vulnerability/

Recent Posts

Phishing Attacks on Your Brand are Unrelenting, AI is the Only Way to Fight Back

When it comes to detecting phishing and social engineering threats, slow response times are detrimental. Automate online brand protection to take…

8 hours ago

Germany’s Anti-Semitic Phonetic Alphabet

Interesting development in Germany to restore phonetics that were erased by the Nazis Before the Nazi dictatorship some Jewish names…

12 hours ago

DEF CON 28 Safe Mode Aerospace Village – Allan Tart’s & Fabian Landis’ ‘Low Cost VHF Receiver’

Many thanks to DEF CON and Conference Speakers for publishing their outstanding presentations; of which, originally appeared at the organization's…

19 hours ago

XKCD ‘Contiguous 41 States’

via the comic delivery system monikered Randall Munroe resident at XKCD! Permalink

20 hours ago

DEF CON 28 Safe Mode Aerospace Village – Matt Gaffney’s ‘MITM: The Mystery In The Middle’

Many thanks to DEF CON and Conference Speakers for publishing their outstanding presentations; of which, originally appeared at the organization's…

21 hours ago

IronNet’s top 10 predictions for 2021

It's December, so you know what that means: Predictions for what's to come for cyber in 2021. We brought together…

2 days ago