New SureMDM Vulnerabilities Could Expose Companies to Supply Chain Attacks

A number of security vulnerabilities have been disclosed in 42 Gears’ SureMDM device management solutions that could be weaponized by attackers to perform a supply chain compromise against affected organizations.

Cybersecurity firm Immersive Labs, in a technical write-up detailing the findings, said that 42Gears released a series of updates between November 2021 and January 2022 to close out multiple flaws affecting both the platform’s Linux agent and the web console.

The India-based company’s SureMDM is a cross-platform mobile device management service that allows enterprises to remotely monitor, manage, and secure their fleet of company-owned machines and employee-owned devices. 42Gears claims that SureMDM is used by over 10,000 companies worldwide.

The issues identified in the web dashboard are also of critical in nature, potentially allowing an attacker to gain code execution over individual devices, desktops, or servers. Furthermore, they could permit the injection of malicious JavaScript code as well as make it possible to register rogue devices and even spoof existing devices without any authentication.

“By chaining the vulnerabilities affecting the web console together, an attacker could disable security tools and install malware or other malicious code onto every Linux, MacOS or Android device with SureMDM installed,” Kev Breen, Immersive Lab’s director of threat research, said. “An attacker does not need to know customer details to achieve this or even have an account on SureMDM.” Read more:

Leave a Reply

Your email address will not be published. Required fields are marked *