Hackers exploit Check Point, Arista and F5 gear

Published

CISA has added four vulnerabilities to its Known Exploited Vulnerabilities catalog, and every one of them sits in the kind of equipment that stands between the internet and an organization's internal network. Two are in Check Point products, one is in Arista's VeloCloud Orchestrator, and one is in F5 BIG-IP APM. All four carry base scores of 9.3 or higher.

The agency's alert, published on 22 September, says the additions are based on evidence of active exploitation. It does not name the attackers, describe the campaigns, or say how many organizations have been hit. KEV entries almost never do, and the absence of detail is not a sign that the exploitation is small.

Three of the four need no credentials

Ordered by severity, using the scores and descriptions published in the National Vulnerability Database:

None of the vendor records describes an exploit chain, so treat any account of how these are being used as speculation until the vendors publish more.

Why a management plane is the prize

A VPN gateway is a target because it faces the internet. A management server is a target for a different reason: it holds the policy, the credentials and the reach to every device it administers. Both Check Point entries and the VeloCloud Orchestrator entry fall on that second side of the line, which is why this batch matters more than the raw count suggests.

Both vendors have been in the news for adjacent reasons in the past fortnight. We covered a separate pre-authentication root flaw in Check Point's management and log servers on 22 September, and Sophos X-Ops research into a memory-only PHP web shell pulled from hacked BIG-IP APM appliances earlier this month showed what an attacker does after landing on that platform.

Patch, then check whether you were already hit

Binding Operational Directive 26-04 governs the federal response. It tells civilian agencies to prioritize remediation of KEV-listed flaws on publicly exposed assets that hand over total control of the asset after exploitation, and to defer lower-risk work. It also sets expectations for something patching alone does not cover: checking whether an attacker got in before the fix went on. On appliances that terminate VPN sessions or manage other devices, that check is the part most organizations skip.

CISA encourages every organization, not only federal agencies, to work KEV entries first. For these four that means applying the vendor fixes for Check Point Quantum Security Gateway and Management Server, Arista's on-premises VeloCloud Orchestrator, and BIG-IP APM, then reviewing authentication logs and configuration changes on each one for the period before the patch landed.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions