Hackers Attempting to Exploit Grafana Vulnerability that Enables Arbitrary File Reads
Grafana, an open-source analytics and visualization platform, has been targeted in a significant exploitation attempt. On Thu, Sep 28, 2023, security researchers identified a spike in attempts to exploit CVE-2021-43798, a path traversal vulnerability…
Grafana, an open-source analytics and visualization platform, has been targeted in a significant exploitation attempt. On Thu, Sep 28, 2023, security researchers identified a spike in attempts to exploit CVE-2021-43798, a path traversal vulnerability allowing arbitrary file reads on unpatched instances.
On September 28, 110 unique malicious IP addresses initiated exploitation attempts. The attack predominantly targeted the United States, Slovakia, and Taiwan, with a distribution ratio of 3:1:1. Notably, 107 IP addresses originated from Bangladesh, with the remaining sources in China and Germany. The infrastructure used for these attacks appeared to be disposable, as most IPs were detected on the same day of the attack.
Payloads adhered to typical traversal patterns, aiming to access system files and Grafana configuration data. This could lead to unauthorized access to sensitive credentials and settings.
Traffic analysis showed consistent geographic targeting and similar tooling fingerprints, suggesting centralized orchestration of the attack kits. Notable IPs from China, including 60.186.152.35 and 122.231.163.197, focused on Grafana path traversal on the same day.
Grafana, an open-source analytics and visualization platform, has been targeted in a significant exploitation attempt.
The continued exploitation of CVE-2021-43798, despite available patches, indicates the necessity for vigilant security practices.
Organizations should ensure all Grafana deployments are updated to the latest secure release to mitigate CVE-2021-43798. It is advisable to inspect web server logs for unauthorized traversal requests and audit any accessed file contents.
Blocking the 110 malicious IPs identified on September 28 and utilizing dynamic IP blocklists with JA3/JA4 signature support is recommended. Maintaining strict patch management and proactive log analysis can help defend against legacy vulnerabilities and coordinated exploitation efforts.
Based on reporting by Cyber Security News.
