CVE-2018-25117: VestaCP Debian Installer Malicious Backdoor Supply Chain Compromise
VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious code that resulted in a supply-chain compromise. New installations created from the compromised installer since at least May 2018 were subject to installation of Linux/ChachaDDoS, a multi-stage DDoS bot that uses Lua for second- and third-stage components. The compromise leaked administrative credentials (base64-encoded admin password and server domain) to an external URL during installation and/or resulted in the installer dropping and executing a DDoS malware payload under local system privileges. Compromised servers were subsequently observed participating in large-scale DDoS activity. Vesta acknowledged exploitation in the wild in October 2018.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Do not use VestaCP Debian installers built from VestaCP commits a3f0fa1 (2018-05-31) through ee03eff (2018-06-13). Verify the git commit of any installer before deployment and obtain installers only from a verified, clean source or rebuild the installer from VestaCP source that is confirmed not to include these commits.
- Compensating control
Prevent further DDoS participation by blocking or rate-limiting outbound traffic from affected hosts (apply firewall/ACL rules or egress filtering) and otherwise restrict network egress from systems that may have been installed with the compromised installer until they are verified clean or rebuilt.
- Operational
Identify systems installed using the compromised installer (new installations since at least May 2018). For any system suspected or confirmed compromised (evidence of Linux/ChachaDDoS, dropped payloads, or participation in DDoS), immediately isolate the host from the network, reimage or fully reinstall the OS and applications, and rotate all administrative credentials (change VestaCP admin passwords and any other potentially exposed credentials). Invalidate existing sessions and keys.
- Operational
Audit installation and network logs for signs of credential exfiltration during installation: search for occurrences of base64-encoded admin passwords and server domain being sent to external endpoints and investigate any connections to unknown external URLs made during installation. Record indicators of compromise for remediation and threat hunting.
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25117?
CVE-2018-25117 is considered a high severity vulnerability due to its potential for a supply-chain compromise and distribution of malicious software.
How do I fix CVE-2018-25117?
To fix CVE-2018-25117, ensure that you upgrade to a version of VestaCP beyond commit ee03eff.
What does CVE-2018-25117 affect?
CVE-2018-25117 affects VestaCP installations created from the compromised installer between May 31, 2018, and June 13, 2018.
What type of malware is associated with CVE-2018-25117?
CVE-2018-25117 is associated with the Linux/ChachaDDoS malware, which can be installed through the compromised VestaCP installer.
How can I tell if my VestaCP installation is compromised by CVE-2018-25117?
You can check if your VestaCP installation falls within the affected commits and is running an outdated version to determine if it is compromised.