CISA Warns Patched Pulse Secure VPNs Could Still Expose Organizations To Hackers
The United States Cybersecurity and Infrastructure Security Agency (CISA) yesterday issued a fresh advisory alerting organizations to change all their Active Directory credentials as a defense against cyberattacks trying to leverage a known remote code execution (RCE) vulnerability in Pulse Secure VPN servers—even if they have already patched it.
The warning comes three months after another CISA alert urging users and administrators to patch Pulse Secure VPN environments to thwart attacks exploiting the vulnerability.
"Threat actors who successfully exploited CVE-2019-11510 and stole a victim organization's credentials will still be able to access — and move laterally through — that organization's network after the organization has patched this vulnerability if the organization did not change those stolen credentials," CISA said.
CISA has also released a tool to help network administrators look for any indicators of compromise associated with the flaw.
Tracked as CVE-2019-11510, the pre-authentication arbitrary file read vulnerability could allow remote unauthenticated attackers to compromise vulnerable VPN servers and gain access to all active users and their plain-text credentials, and execute arbitrary commands.
The flaw stems from the fact that directory traversal is hard-coded to be allowed if a path contains "dana/html5/acc," thus allowing an attacker to send specially crafted URLs to read sensitive files, such as "/etc/passwd" that contains information about each user on the system.
To address this issue, Pulse Secure released an out-of-band patch on April 24, 2019.
![pulse secure vpn vulnerability pulse secure vpn vulnerability](data:image/jpg;base64, /9j/4AAQSkZJRgABAQAAAQABAAD/2wBDAAgGBgcGBQgHBwcJCQgKDBQNDAsLDBkSEw8UHRofHh0a HBwgJC4nICIsIxwcKDcpLDAxNDQ0Hyc5PTgyPC4zNDL/2wBDAQkJCQwLDBgNDRgyIRwhMjIyMjIy MjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjL/wAARCAFMAtgDASIA AhEBAxEB/8QAHwAAAQUBAQEBAQEAAAAAAAAAAAECAwQFBgcICQoL/8QAtRAAAgEDAwIEAwUFBAQA AAF9AQIDAAQRBRIhMUEGE1FhByJxFDKBkaEII0KxwRVS0fAkM2JyggkKFhcYGRolJicoKSo0NTY3 ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqDhIWGh4iJipKTlJWWl5iZmqKjpKWm p6ipqrKztLW2t7i5usLDxMXGx8jJytLT1NXW19jZ2uHi4+Tl5ufo6erx8vP09fb3+Pn6/8QAHwEA AwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoL/8QAtREAAgECBAQDBAcFBAQAAQJ3AAECAxEEBSEx BhJBUQdhcRMiMoEIFEKRobHBCSMzUvAVYnLRChYkNOEl8RcYGRomJygpKjU2Nzg5OkNERUZHSElK U1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6goOEhYaHiImKkpOUlZaXmJmaoqOkpaanqKmqsrO0tba3 uLm6wsPExcbHyMnK0tPU1dbX2Nna4uPk5ebn6Onq8vP09fb3+Pn6/9oADAMBAAIRAxEAPwDx2iii tjIKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiii gAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKA CiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAK KKKACiiigAooooAKKKKACiiigAooooAKKPzPsBXufgD4QWsVlFq3ieLzp3XelmT8kQ65f1NJuwWP EYY2l3FYZZBg4Mak4PvUR4baeGHUEYI/Cvqc+J/D1hdQ2thZR3Fr5Jlkms4VdIVDbfmA561Pqfhb wt4z0wSPaWs8bjKXNthWU+oI7/WtKlKpTSlOLSYWXQ+UaK6nxz4JvfBWrLbyuZ7KbJtrjGN4HVT6 MK5/TtPudU1C3sLKLzLm4fZEmcZPpUAVqK19a8Max4faBdRszH5+7yjG3mBscHkelQaLo13r+px6 fZhfOcNgyHCjAJOTQBn0Vs6N4V1jxA10NNt0l+yuElLSBQCTgDJ61nXthdaddTW17BJDLC+yQMPu sO2elAFeitGx0S81HT9SvoFVYtOiWaffkEqzbRtHfms8qwzmNwAdp+U8E9AffnpQAlFWr3Tb7TL2 WxvbWWG5hAMsbLyuQDk49jWlong/XfENpJdaZaJNEknlEmQLl8Z2gHqaAMOinyQyxSvE8UiujmNg QeGBwV+vtTSrBgCjgt0BUjP0oASinbG5GyTKnBAU8fX0qxf6be6VOsF/bSW8rIJAsg5KnoaAKtFF FABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUU AFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQA UUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFAHX/DDR4tb+IWmwTqHhg3XLgjg7MY/8eIr6 F1y7ni13SrdJWWGeC781OzbUBGfpXgfwi1GLTviNY+cQq3MUlsCf7xwR/wCg4/GvdPFMq2esaNfX O6OzjFxFLOEJWIugALY6D3rbDq9W3k//AEl/qHQ4e0WCwl0G6WW4smOhRySXVrHu2tuA3Sr/ABLx g/nWrPcT6cupXtv5dpqdrZrf+fZn/Rr6JiQCyHoTj/69V5ll0zTLZZ5/sdzBp7WcF6gEtpeRYJ2k /wALE9M9/WoXUnQZgikn/hDrbAUZ/iavoJWm1J7Xt6rm/K3TX0TROx0fxT0lNZ+HOoMVzNaRC8iO M4ZeTj6jI/Gvnrwjqltoni7StTu9/wBmtZxJJsGTjnoO9fR3xG1KPTPhtq0rsAZbTyIwf4mcBQP1 r5ctoGuLiOBcBmOAT2r5eJbPXpfiN4Xk1O2uHe7ke3jmCXC22xRvYEKU/Dr3qWD4meFre9mlt/tV mjXMkrJHaj/SQyYGTjK4NeXS6TELdmhlYuoyAxHPGcYA4yOaZeaS0UzeS8ZiBUHL/MuQCM8U+VC5 je8MeLrbw9pOuqbeOe7up45bVJ4t8YKsSC3oRxXTW3xG0GXw5ImrRTXmozhZLmJ4Mo8okDHB7AjI FeeRaJOLuKK4MccbOi5LEbs9hx1xVRLRp9Qe1g25DMAXOAAuTyfoKfKguer23xJ8P2mt6hfTTXeo WtykQitJLVUWDbLuKDAGcDkZ7gVn3Xj/AEeLwpeWNg0kmosZ9ks1t/r2eTckuRwrLx1/u157HpFz LMkcTRMXUMhDEhwfTj270+10t3uII5tuZlZhEpPmH5GKnA9SB/k0uVBzM9O1L4i+Hb6bXp3nu5E1 KJRHCbba8bCPbtD/AN0NnOeua57wN430/wAMaDHZXVv5839ppO52Z8uPYVLoezg9K5GLRr2VZNix uYztO1s5YLkqDjqO/alm0iVN5SeGSNIkldwTxuAIHSnyoOY9OtvGvh65stP0e03SSm4SNjc2+PMP m7vNLdAxHJz3q1q/j7w9Za7JaTGa5kgubgfbVtkza7hhQgAwwHrXi36fjR/nnvS5UO56bq/xEsP7 N1QaO8iajNFBFFdyWygylc73IxhSQawPH/ia18U6hYXdtcTv5dqsUkMse3y3HXB75rkaKLBcKKKK YgooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKA CiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAK KKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigB0UjwTRzQu0csTh0cHlWByCK+lPAPxI07xZ p8dlfyxW+sKgWWCQgLP2ymeDn061800dGBGQQcgg9Pp6UmrgmfVmo+EGjiuf7CuRY+epEtpIm+2k zxnZ/CfcflTdF8PaT4K0/wC23V15bLaRwTyzynyhtGW2g9Mtk4FfOdp438U2EIhtvEGoRxAYC+cT j6Z6Vm6jq+pau4fUr+6vGHTz5S+PpmuiWKrypum5aPfz9X1Hodl8TfiAPGGoRWWn7k0e1YmMkYMz 9N5HpjOBXCQzPbzJMhAdTkUyisBGlc6u8tuYkTy933sEHtjjjPTj6Un9t3IfzVSFHJBchPv4GBms 6imBpnW7kurNFA2wqUVkyFK9CKba3trBdi5aKYy4csSVKkspHTA9fWs6igRpQ63c27KYooFVSuxA nyptzjH5mol1OcPDKFjE8Q2rLj58bSvUegPFUqKALx1WcrKpSI+Y284XGHIwWGOhOBntnmhNVnjc OqReYIhEJCvJUDAz68YFUaKAD/PNFFFIYUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFAB RRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFF FFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUU UAFFFFABmj+nX2qzY6idLuDdi0s7sqhAiu4vMjPvgEc8V6F4o0yLUNbl0m00/RdK0+1sIb+7vltm VoQyAkZBJOWYAKBk0rhY80zRXZ6R4R06XXvDzvq8V7oeo3otjNFFIpMoZcwspAZCQww3THNZ40HS Ztbv7ePX0S2hkxHILKZ2cktlQiqWwuMEn1p3Cxzme3f0oruL3QW0Hwb4s0+8WGW7stSsoxMi/wAL AsCpIyAQRxXOQ6HNceGptYgmWTybpLaW3Cncu/7rZ9CcD8aLhYyqMiuk17whLoWmXl699DP9knjt 5Y0Ugq7oHxn2BAPvW1D4eGh6L4ttrkw3Mq6ZbXEcvl/6vexPGeh46ii4WOBortbz4ffZru605Nes 5tUgtPtn2MRSDdHgE/MRtDc9Kgs/AVzc2tqH1CGLU7q2N1b2Jiclk2lgC4G1WIBIBpXQWORoro7z wtBp+k6Xd3es28M2pxJLDbGKQlFLbWLsBgAcn3wa0rPwmllqXh/Vbe+j1GwfWrazmBtni+YurYKy AblIB5HFFwscVn/Ggc12HiLwtbm98ST6dq9pc3OnzTT3NjFG6+XF5pB2sQFbZuAOOn4Vf8R+GBqX i3VJhLDp+mWVpZNNMICwVngTCqiAliSSeB79qLhY4CitTxDoc3h+9jt3njnimgW4t54wQJI2zg4b kEEEEGvS4tDt3vdIsX8LWDaFNpST3momFkeJiGywl3AZGBxjvTuCPIKM10beEX/tPQLSK+jddaj8 yCQofkUk43ev4Vu/8Iy2oeFdB0i3Fut6+r3kD3JXG4JvySRyRheBRcLHn9FdNB4ShvdYey0/WIp4 LeBp7u5e3kj+zqpwcow3EkngDrVPXvDzaNFZXMV2l3ZXqM0E6xvGTtJVlKsAQQRRcLGLRXfabbrH 4Osb/QdB0nWpo0dtXF3G008L7jgBAwIj29GA/GsjR/Bx1Oxsbq51KCxOpSsljG0MknmYbaWYqCET cdoLdcE9M0rhY5iiuji8KC3svtWvarDpKtcyWsSSRPK8kkZ2yHCA4VTxk0x/CsouvD8IvYnGtKWi cKcRgOUyc8n1p3Cxz9FdTJ4NS20qfUL3WIIUjv5dPjj8l3eWRCQNoA7479KmuvAFxbWl0P7Rgk1K 0tvtM9isT/ImASA+NpYAjgUXCxyFFdN4QsrPWbXWdJlgje9ltDcWMpHzK8fJUH3B6e1a/hvStOi0 zwymoWMU93reqq371cslsp24HsxB/OlcLHBZor0rV9Mil0fVp9W8PWekNa38MWmzQQtCbkGQhkKl juG0A5wOtN8ceHNK/wCEgF7odqkVra6lHp+o2Y+7E29dj4/uOvH1BFFx2PN6K2vEtkkXjnWLC0iS ONdTlggjHCqPMKqPYdK0LzwU0XiCDQLPVIrzVXnME8HkSRiLAOW3MAGUY6jNO4rHK0V2C+ATdzWA 07VoLu2ur1bF5vIkj8mQgkEq4BKkA4IqpqXhNLTTNQu7HV4dSfTp1gu4oYnUoS20EE9RnAyPWi4W OaorsZPAL2r3L32qww21qkQnmELyFZZBuEQRQSSAQSegBobwA9s2ptqGr2tpa2CRSGco7CWOTO1l AGc8dKLoLHHUZ/wrpNS8LQaXo8N7c6zD511CJ7a3FvJ+9jJ4+fG0EjnBPFW/BFjbX+meLEunt4VX To2FxOm4Q4lGWGATnAxxyaLoLHIUV1a+CDcpHPp2rW95bXFpcT2sixuhlkgGZIdrAFX25I9QKxLr SjaaFpepSzJ/xMGlMUAHzCOMhd59AWyB/umi4WM//DNFb8Phy2j0m0v9X1q2043ytJaQvE8ruina XO0EKpOQCfSrdr4LWRrC1vdatLLVr+JZrexkjkY7WyU3OBtUtjjJ/nRcLHK0f/qrbuvDFzZ2ulSz yoj393JaGIg5idHCNk9+T29K1JfA8dnDq1zqOu2tpa6berZyyGF3LsVBBVVBJ6ii4WOQor0DT/A+ nWlxr9rrWox77OwFzbTRxyMmxsES4HXuNvXis618E20tvo8k/iK1tzq5xZqYHJY7tozxxk46+tK4 WOQorftvC7fZ7y51G/i0+C1vlsWeVGbLnkkAc4AwT/vCsKRVSV1VxIqsQHAPzD159aYDaKKKACii igAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKK ACiiigAooooAKKKKACiiigAooooAKKKKAGyDdEy+oI5rt7nxrY3et3sk9jcvpeoabDYXMIZRKvlh cOpzjhl6HGc1x0EJnuI4QQpc4ye1azeHJkUs08eB14qlBy1Q0aCeKNP0yXQ4NHtLo2OmakNSlN2y iW4lyoIwpIUBUAH1q3Z+KtF0+HVrWzGu2sN7drdpc2zxx3BwDuhchuEycgqc+1S/8Kyvdo/4mMPP ODG1cbf2cmn6hc2UrB3glMbEdGI4zWacZbGk6U6dnJHVeI/Gllrdv4jSG0uYzqt1ZzxeYV/diFAr Bjk5JxxVHwd4ktvD19c/2havd2NzGA8CYyXVgyHn0YA1mXGh6hba8NFmhC6gXSMR5/idQV59ww/O qV1A9ldz2txhJoJGhkXPRlJBH5inZGWp0lp4msbzSdV0/wAQw3kovr37f51mV3LJzlSGI+Ug49qv 6t41sL/+3VgsbmKPUdPgs4gxUmMxlslue+e1clFYmXTLi+FxbosLqhiZ8SPuOMqO+O9R3drPYXDW 91E0MygFkfqMjI/nRZBdnXyeNLKTxxd699kuPImsGtRH8u8MUC5POMcVYbx/Hc6VapPd6/bXkFoL Yx2U6rbykLgMckFfcAHNcDkbc5GPWr76VcJoMGskobWad7ZcH5tygE8enNOwXNz/AISu2F/4SuXs XuF0SBIp4pMYmIYkkfnkZ7gVrXfj6wktLSBTrd40Ot2+ptNfyIx2R5zGoDEL14xwa5fR/C+ra7DJ PYwR+RG/ltNNKI03YztBPU8iql5pV7p/2g3EJVLaf7NLICCgkwTtB78DNKyHdnQ6h4l0RBr9xo1j qEd/rSSQyG6KeXBHI++QLtJLE4HXGM1op8QoBqersBqdrZ6jDaqJLN1W4ikhjVMjnBU4OQT0Nef7 hzyOBkjPSp7m0uLOVIrmFoneNZVDd0YZVvoRRZBcveItUGs6l56XGoTRLEI0e/kDynGSehIAyegq 34n8RnXf7PSFruO2trKO2eB5PkZ0JJYKDjnI688Vz4YFcgjHrmgEHuOeOvWmI7jS/F+hRf8ACO3O qafqEl7oieVH9nKeVKvYnJBBHsKrS+KdOu9PsbO4i1GIQalcXpltmVXXzCxXacjkZGaw9F0K/wBf uJbfT0jZoY/MkMjhFVemc0+Tw5qaa2ujpCk98wyEgcOpHXO7oMUWQanWj4jwRapG6Q6k8LWTWdze F0jvJSWDLJlTjK4xyeQetcz4l1uPWJbfybzVrqOFCC+pyKzlieoCkgDp35xSP4S1dNWi0wJBJcyI ZB5c6lFUdSW7YqrrGh6hoVxHDfwhPNTzInRw6SL0yD3oQ7mz4e1rw5oVzp2ri11k6xZneVikjWGV x2LZ3BD0IwcjNX9O8eRJotpY3c+tWT2bylP7JlVI5kd2k2sCRtILEAjPFcNRSsK51J8QaRquj21l 4gt9SeazmmkgubV0ZnWVtzLJuI5yM7h1z0q5p/i3QkTQZNSsNRkudEZlgEDJsljLbgGJOQR7cGuK op2C502r+KIdQ0dLWCCWOddYm1IO+Nu1yxC9eoyM9q1dc8fRaxaXDrda/BdXEQRrVbhfsitgAkc5 IOOmK4SiiwXL+h6m+ia7Y6lFkm2lDFQPvL0ZfxUkfjXQah4wtbzx7pmtw2ksOmac8YgteNyxr1HX GTXIUUAX9Q1KXUNae+mmuJVNx5qCaQuyruztGSQOOOOK6KPxrDF8QNR137LJLpepSEXVm+MvHkEd 8blYAg57e9cdRRYLmlrGowar4o1DUzFIttd3slwY+N4Rn3bc9M4P0zXWr8Q7ewm0hrGLUb1tPuWm NxqTJ53lFChhVlJJHOck9QK4CiiwXO6Pje0j1bS7pLzxFeQWt2LiSPUJkb5QCAqgMctyPmOOlZvh vxTbaN4j1C9urSS406+Mhlt1xuOXLoeTjgmuXoosFztdJ8eyxRavBfzalANQu/tgudOkCyxt024Y gFcYHXtVa+8WQXema7aZ1Kdr/wAkQzXkokdRGSfmOeOvAGa5OiiwXOtt/FGnWfhS60iJdUuTcwBP IvCjW9vJkEyRnJYewAHWqXhfW9P0i31q21O2uZ7fUrVbci2Khkw+7dyR/wDXrn6KLBc7fTNXludY 8M6Z4TsLpotLujcA3JXfM0jqJGfaSFTb8v0rH8aX9re+KLiLTgF0yxVbGyVTwIY8jIPfLFm/GsSK ee3ZmgnliLKVYxSFCynqDjsfSogMccADgYotqFzpn1nQ9T0XT7fWbXURe6dbtaxS2ZTZLFuZlDhi CpBY8jOavx+K9DuLvTdY1LTr6TWLCCOLZAyfZ5zGMIzEncuOMgA5xXF0UWC52MPizSr20sxr1pfS XdnqEt9E9mUCSGRtzK24gjkDBGah8QeK7XWNK1y0htpo21HU1vYzJjCKEC7Tg9ciuUoosFzuH8a6 bcaxeTXNnefYbzSU06UR7fNQr/EATg/nWPquq/2xY6BpmlQXX2jToWhjJA3u27cpGD1GBXP0+KWW CVZYZJI5FOVeNyrL9COaLBc9A8fataS63penX0LpDCBc6pHbMN5uJFHmbSeMjAHNefSFPNfygwjy dgbqB2zikZmdi7szOxyWJySfUnvSUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUU UAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFAGp4bt kvPEVjbSsyo7nJB6YBP9K9RbwxaupDXU5BGD93/4mvHobia0uEuIJWjljOVkBwV/GtL/AITDWv8A oMzf99ik3NfCzejKkl76PbhJ05FeH+JmH/CVas2ePtLnP40o8Ya1u/5DM3/fYrMlle5leeZ2eSQ7 ncnlie9RCDi9TTE141ElE9G1awvbj412s8NrNJDczWc8UqoSrIIowWz0wMH8qW/1K20vw/eavbaf Y3dxceJrmJZ54t/7sl24+uK4uLxRr1vpv9nw6vdR2m0qIg/3VPUA9QPoao/bbn7Alj57/ZEl85If 4VfGNw98E1djluek63p1hpNr4purSwt1eG8sJIQyZEfmBCyj2OT+dat/HBqvjrXJtRt7cf2bYJNa ZtDIGZlXLFV5fb6D1ryi41nUruK4invpZI7koZlJ+/sAC5+mB+VTnxNrZmtpzqtz51smyF8jKKe2 e4+uaLBc79bbQ7+7bUrW0ivdQs9KluDALJ4IrmUMArBD1wM5xWR4jvLm/wDhfot1dWEVnJJqU2Vi iMayAKAG2n/PFcq/iLWZdTj1JtSuDexDak4I3KPQY4x7Ypuoa7quqxLFqGoT3CK5kVZCMKxGCQO3 aiwXNnQ7+2uNBTQdc0e9u9Ke6MtvdWcbGSCUgBiOMP8ATrXQ6rHfeG/h7rfh+Fba6FprYs/NEGSU aFm3E9mGcZ7dK4jTvEmtaRatbadqc9tCx3GOPGAT1PINQw6zqVvFeww30yx3oxcoTkTZzndnPr16 0WC56Nq2mQW3hnxHa3MVi97okEMiC30941hkWRAQZScSZBOfXmr90Idf8bWMWp2lube20KK+hUWx IllEAO3A5dR12j0xXmV14n129sntbrVrma3aMRPG7DDoMEA8c9B1qP8A4SDWNlkv9pXAFjzbYbmL twfz60WYXO7lu/DH9oaRe3dv9rnUTrPLbaY8URGBscxnO7YeuD0NYfildR0+7uFls9OuIr2yR1ub W1ZVWPccOBzsbqDmsV/FWvSX0d82rXBuolZY5Pl+UHqAMY5qCfXdWuWumn1CeQ3SCOfcR86jop9B 9KLBcu+HNYGlJqaS6Q+pW97AIJkR2XauT3UHGeldzpmj6V4fudamtLK4c3GhJdRaczkSx7m+dMjn 0968303WNS0aWSXTb2W1eQbXKY+YDpnINIusakmp/wBpC/uBfE5M+/5j/n06UNAmdXd+E4dXh0a5 0mzXSDqFtLLewSMdkEcbYMmOCVPGB3JFY/iTUbWW10zSNNinGnaZE0cU06FWmZmLM2OwyeB6VVTx Rryak2orqtwLxk8tpcjJTIO3GMAcVDqeu6rrKxjUr6W5ERJQOFG3PXoBRYLmfRRRTEFFFFABRRRQ AUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFAB RRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFF FFABRRRQAUUUUAFFFFABRRRQB0fw/s7e/wDiBolrdwpLbyTtvjcZDYRiM/iBXv8A4puPD/hiyimf QrOaWZiscYhUZx1JOK+fPA+pWujeONI1G+fy7WGYmSTGdoKMuTj6ivcfEHij4e+JLJLe78RW6GNt 0ckZYMhPX+GsqvNb3dzqwToKtF4j4OtjV8MS+H/EunPcxaJaRSRPsliMKnacZBB7g186eMbaCy8b a9a20SxQQ30qxxgcKM9B7V7xoPiv4feHtPNnZeIrYqz73kk3FnbGMn5cV4P4ku7XWfHGrXcFwI7O 8v3dJ2U8RlvvYHOO+OtFLmt724Yx0XWl7D4b6F278MrJpvhg6eEW61O1nmnaecIgKSFQctwAFFQr 4I12TVbbToYraaW6hee3khnDRSov3sN6j0Nb0eteGRqGk6bcTx3dnpemTQQX09oWiN1IxcOYjklF OBz19K6XRtc03VfEXh62t9RW6ez0+/W5lgtPIVdwUgonAxgH8q0uzmsjza98J6tYQ287raywzy+Q JLa5WRUk/uueNp/T3qS58G6xbNa/8ec6XNwLZZLa5WVVlPRWI6fyrY0vUPC2iaPbaPNenWbO6v47 m7ZLd41jiRflG1jlmJxkdMZFbkvirQoNNtrUanazeVq8Vyos9ONvHHCpHAAAyQOuefrRdhZHG6h4 J1vS7WW4uEtGSCVYZ1huVdoWY4G8dgfX86x72xfT9QeyuWjLxMA5gcSL74boa6iLW9Nf/hNVluio 1ZlFs3lMd4EjEkjtgEda5me2sYNXFtHfmexEqqbtYShKEjcwU5IwM8HPSgR0T6d4f1Xw1rF/pdnd WM2meTtmubkyLPvYrtYdA3G7jtWhf+GNCTUNe8O2lvejVtHsnujeSS5WdolVnBToqsD8pHcD1qv4 rm0i5097XR/ENkmkWvzWulx2syvIem52IwXPdiatyeLXsPDN7bHxTJq8tzYtZQW4tWj8pXADNK7c sVXcFAJGTnPFLUoLfwjpEuiQM1lflJdHOovrgkP2eKUKWMWPu8MNhB+bJrz5SSoJGCRnFelW3ifR I7611g6xMtjDpwtn8OC2bazCLYYw33NjN85Y8+2a80RSiKCQSBgnPWmhMdRRRTEFFFFABRRRQAUU UUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRR QAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFA BRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQBa0vTbvWdTttNsIvMu7l/LiQkAE4J5J6AAE/hXa R/BvxbO8iRHSHeM7XC3uSp9D8vWsv4Z/8lL0H/ru/fp+7evYPFUktl4fu5fCQuGma5Au2gBMqx4O CnfbnuOaTcr2RpThGTSk7Lv2PM3+DXi2OaOFzpKySEhEN7y2OTgba4i+s7jTtQubC7Ty7m2laKZM 52spwRkda+ifCks934e0248VrPHei4YW5kz5rRfw+YeuN2cE9a8P8dHHxD8RHAONRlOCODhqFe7T FOMU/dd13Mr+ytT+wG//ALMvhZAZ+0m2fysdM78YpLDUr3S7r7TYXDwTFGj3pjlSMEc+1drrE7eO UvtX0XWLuKdLdWvdFmlZUiiUBSYiDteMdduARzUg8P8Ahv8A4S5vBn9n3X2pUEZ1QXR3ecYw+7ys bdnOMdaLk2POwMYAHQcClAJYAZJJwB6mu0Xw5pv9q+CbZoWKatbh7sCQ/O24g4Pbp2q/qMum2fw+ ms49JRhHr8tvHIbl8qwyBJjuQBjHSi4WODvLK60+6e1vYJILiPG+N8ZXPIzTIYJ7hisEEkrKpYiN CxCjqSB2HrXqPiSx0PW/GGv6c2nzx38Fh9qF8Lk/fVU+Xy8Y2kHr1rm/hf5Mnim5FxM0MD6VciWR FyUXC5IHfFF9Liscl9nuPsn2ryJPs2/y/P2HYW67d3TPtUf58dq9F1DSX1Pxna+H7qJrPw9p9nLc 2kFo+RLbohcsj/xPIerHnn2rJtbHQ/EWkvf2GmSaW9lqNpDNELtpkmincrwWAKuNp6djRcdjkPy9 vej8R+deiL4e8PXfijxHbwWC21j4fMqstzqPl/a380RoHkbhEB3dOTkDOTUE3hvSDrFtLp1tZ3kH 2J576zj1lPIspFbbl5x0Qgggdc8ZouFjgqP8cYrsfFWmaLoFxZzQ2Kzw6lppkiSG/Lx28wYruV8f vF6cH8653RdTu9H1OG6sXSOcEIHeJX25IBIDAgH36imIgWwvZLsWiWVy10ekAhYyHjP3cZ/SiTTr 6G9FjLYXcd4xwLd4HWUn2QjP6V1fja4EfxO1J57+7s0cxiW4tgTIAYlzgBhnPpnFa1/rFtpl74L1 wT3WoaNaQyxxXTD/AEqRsMpDBsYwTwM4x3pXHY4G90rUdO2f2hp15Z7/ALn2m3eLd9NwGaqV03iG xhn0e28QWOrX19ZXNzJCY78FZIJByRjcwxgjkGuZpoTCiiigAooooAKKKKACiiigAooooAKKKKAC iiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKK KKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooo oAKKKKAL2j6rdaHrVrqtmUFzavvTeMg8EHP1BNd3D8atet5ZJYNJ0iN5Tudgj5b9a4XRLVb3W7S3 kiMiPJzGDjcAMkc/SvStU8CaDb2V9qsWyELb4Fi0u7bIWTDIR1GNwweRmpk4pXkb0MPUqtKHVpfe Z8nxr1+W4iuJdL0l5oT8khR8rnr/ABVwGoahcanqt1qVyVN1cztPKQMLuJzwK9K03wBpF79lvnmj jtjZI0kYk+YyYO7A7tx06CvONYghtNbvraCKSKGKdlSOQhmRQeASOCQOuKIuLXuhXoToy5Z92vuN W98aapeWVzaiDTbNbpPLuZLO0EUky91LZOAe+MZpx8ca2bfZusxceT5H28WwFz5eMbd49uM4zjvT b/wyln49HhoXTOhmhi88rz+8RGJx7bjVeXwtqz6le2+n2NxdxW93LaiZE4YoxH4HAzVaGOpY0vxx rOkWtnBbixk+wk/ZZZ7YSSQg9VVsjiqyeJ9QTT72xZbSW3u52uXEsO4xyMclkORg8+9Frorz2N8j WF+dRhnjhTagEcZJAKvk5BPap9b8G6xo2trpTWslxNIAYjEn+s4BOB7Zwc0tBakLeKtVfWrzViYP td5bm2lPlfKUIAOBng/KOc1T0nVrzQ7qS4smjWSSB7ZvMXd8jjDY9+BzRJouqxakmnS6fcretysB T5m9x7e9auqeGJtH8JWmo3sE9vfTXslu0Mg4CBQQR+dPQCtZeK9Y0+0sbW3uEC2EpktJGTdJDkYZ AT1Q5OVOepp174s1K9S3QRWNpBDcrdCCzt/LR5QcqzjJJxzxnGD0qbSPCVxrfh+O+sWL3Umo/YhC RhVURhzIzdgMnPsKjvtM0q3TWRZTXl+lj5Kx3kaAQhmYhy3OdpxhcdTRoGpBb+JtSttbvtXjMDXF +0hu45Ig0MwkbcylD2zyOeCKsR+MNSgvZbiG20xI5bf7NJaLaDyHjzuAK5yTnnOc1Tu/DmtWFrLc 3WlXUMEJ2ySOnCHjr6devSltPDet39qlzaaTdzQOdqOicMenHr9elAFu+8Y6rqP/AB8xWD7bRrNA LUYjjJz8gzwR2NYCko6sOqkEZ9q0tM0HVNVfda2FxNAkoSWSNeE5wfxHPStDWPC1zF4t1LR9Htbm 8W0dQCBkgFVOSenc0aAVz4o1B9dn1iaKynubhNksc1vviYAAD5SeOAOQaWfxXqVzqFpdzRWLLaIU gtRbD7OinqNnfPqTn3qmmh6tJezWS6dctdQjdLCE+ZB6kelWP+EW8Qb5U/se83RLucbOg659/wAK NAG6v4hv9Zit4LgW0Nrb5MVtaxCOJCepxyST6k1lVPJZXMFpDdS28iW8xZYpCOHI4IH0rd8O+FYt c02/u31O3he1tpZktgd0snlgEkjsvI5oA5uit3QdN0G/WBNT1a4tbq4nEMUcFv5gXJADOT2JOMDn irVp4SWObV21e6lhttNu2sGNpEZZJ5xuyqL7BSST04ouFjmKKnvFtkvZlsnkktg2InlTa5HuOxzm oKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooo oAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiig AooooAKKKKACiiigAooooAKKKKACiiigDT8OpDL4isYrgwrC0mHadyqKMHqR/nNej6jH4TzfW2nR lbmC185ZTL1YOqng+oY4HWvJ0RpHCqCzMcADqas/2Xf8/wCjSdfasqqpvSdj0cDiMVS/gqTV7u17 ee3c9W06y8LXdraWoWN9Ye0Wd45pyizbgT8h6ZGOVNeU6qU/ti9MKosfntsCHKgZ6A0f2Xf/APPr J69RxVUqUYqRtZTgjHSikqa+BonG4jFVf46aV21e/wCvY9NuLC31Txxa+MItW06PSGNvcTmSfEkJ jjRWQp3OU4rM1TxAZ/BLy2N68D3XiOa5MSSFXEbbmUkDnHIrgC0QbLFNw9cZFSmNkVWZGUMPkYqQ G9cHvWljhuen+KNTtZNM8WNDeRtJNcafIux/mfCx7iPXGDmtIXlonjDWLiS7tZl1bTkTTybsoNwU BlLjmMn+lePeUwQS+U/l5wH2naT6A9M03aozwvPXjrRYLnrK6sDe/wBkSNZabff2TNbWU6Xxn8tm YHa0hAKkgcVgeJEms/hzpGnXmpQ3l9DfzM6Rz+aYlKjAJrhQoC4AAHpigKo6ADtwKLBc9D8J+IrL RPh7cW99+8trzVXhu4o2xKIWhQF0xzwR+OCO9UZ9Pg0Lwv4105L+3u450sJLSSN/9dH5rHOPUDqO 1cUCN3YkcHnpTQULYG3d6Dr/AJ/xosK56jrGtfa/iF473akZbKbSLqKENLmN2EKbAo6Z3ZxjvWno aT6n448M6vp2swR6QltbwC2E5VkZU2vEYx1JbJz71478owOB3ArpLLxfPplugsdJ0u3vVh8kX6Qf vgMYzn+9jvRYdzpF83VdH0BtJ1i3s0026mN/G9yYSrGUMJCB94FQR/8Arq/4gnTW5fE2naNqlvBf PqcdyWM/li6hEQGA49Dg49q8o2LxkA46ZFBVSuCAR6YosFz1d9at4ItStxqUcmo2vhz7NLdxyf62 bJ4Vu5H9aq2evOJfhyG1N9sW4XeZjx82Pn/D1rzLA44HHT2owPQc9eOtFgubmv284Z7r7bHJZTXl x5ECTFvLw5ydnRQevHWrngaeG31DWWnlSMPol1GpY4yx2YUVy+AOwoIz2B+tMVzuvCGk+RoSa9Yr ZXOtGdkto7qYIlptx+9Kn7zE5x2HWrekXOsDw1qOg2Gr2lpr0OsG8nlklX9/G8agsHIIOHAJ9jXn LIhbJVSfcUpVduNowOgxRYdzoPG11Z3vi69nsJIpIiIleWEYSSURqJGUehYGsCiigQUUUUAFFFFA BRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAF FFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUU UUAFFFFABRRRQAUUUUAXdJ/5Ctt/vE/oa765az2p9lWRVEYEokOcye3tXnVrcfZruKcDOw5x69q2 /wDhJY/+fVv++68nMMLVrVIygr2R9NkePw2HoyjWlZ3v17Lsb1cZeR+brU0QIUyXGzJ7ZYCtX/hJ k/59W/76rCuJjcXUk/3S7bsA9Pxq8Bh6lKUnNW0DPcww+JpQjRldp+fbzO58ReJ77wr4gvPD+gLH ZWOnP9nx5IZ52AG53J5Ykn8quXFho2q+GvBFvqt5d2891HPHD9mjUgFpBlmJHTOOBz71gXHizTdV ZLrW/DVvfamqKjXYuZIvO2jCtIqnDHHBPcVTl8TvKvh8fZY0GjFygDH95ucNg+mMYr0j5o6G18IT XFppuk3eq3CwPr01i0SKuxGRX/eLxnJ2/TBrN1DwxpA0e/vdJ1C9mbTr1bW5WeJfn3Nt3IFAPXsc 5qSPx9LHc20/9nRHydVl1PG8/MXDDZ9Bu6+1Z+m+LJ9Li1FYbWNnvL2O8Bc/cKPv247jtRqGhr6r 4Hs7Lw+2rh9WghgnijnW8iRWeNyAXRRyMc8NXHXi2qX0q2TyyWgf900oCuy++OhrqtQ8b2t5p99Z JoMccd9cx3NyWupJC5VslQSeFPIwOma5S8lgnvZpra2W1gdspAHLBB6ZPJ/GhCZ2+sfZde8L+DRB YW2mx3eoy2xjthgKpkVM56k98mrt9fNrGoeMvDzW0K6bp1lPLp0McQBtngdQu0jnkEg+ua4qfXJZ fDulaSsQiOnTyzpOp+Zmdgw47YxWtqHjUXaX9xaaTBZarqQUXt9HKxL4ZXOxTwm5lBOOuKVmPQ24 dKi0TwJ4n0ma18zWWsobm8kCZ+zEzJsgH+0FYs2O7Y7V5z7+vNdXB8RPEiafqdrcand3JvYBEryS n918wYkfUAr9DXKAY4AwKpCYUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUU AFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQA UUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABR RRQAjHCk/wAhUPn/AErc8M2bah4jsLRGRGmdlBfoPlJ5/KvVP+ECv/8An6tPyb/CvMx2aUcHNQqO 11f+tD1svy6jiqblUq8jTta1/wBUeH+f9PyqYN8m7p3PtXtX/CBX/wDz9Wn5N/hXlOrxf2f4ou4Z sSC3u8PtPDAHkD8qMDmdLGScabvZXFmGX0sLBSp1ee77W/Vl1fCVxHFbvqesaLpMtygkit7+4dZS h+6zBEbYD23EH2rAuNttNJC8sbFHZNyPuVsHGVPcHHB7ivS9V8OTaz8Q7nVW0O71zRNXlSW3ubOZ kVEYKMllBwUAIKnHStTS7W20bR7tNAXWHkh1meCdtKhjnlaNGxEshYg7CM9ODXpXPLseOmRBjLKM 9OaTzoum9M+mRXp+t6zPpng7W7rRYZdIM2tbPKIUSRAxksoxkLlgeAe+K6BdWvR47i0cmN9O/sFZ 2tXiVkaQLkORjkjjk0XCx4iJUKkhlIHUg9KQSoQSHUgdcGvVNKXUPF+heFNQudQCaqLy6UXjQJJI UVWYIqnhjxwD0/Cuhgjknv8AwTe3kGotdm/uo/M1ZE+0OghYgMFxhc9Ac8e1FwseFiVDnDqcdcHp SllHJIAxnJr0i28U6i3hq81q+kF3PouuwNakouUiYN5kS4HCkDGOnNO1q0n8KNDZeG2Mmoa3qa6h ZPAA7G1TmAAEYOXZzg/3RRcLHntlaXGo3tvZWkRluLmRY4YwQN7McAZNbF74UnsrcXP9r6Rc2i3X 2O4ubad3S1lPIEnyA7Tg4ZQwOKTwnD9p8e6XDe3slk7X4MtwCFdJAxJwSMAluOmAT0xXUeJVvJfA +rT6poEXhuVNVSWK2hRkW9ZiQwYNksUBLBlwvXgZovqBzNx4UMWg3esW+v6Ne2tq6JILZ5txZjgK N0agnvjPQVz9dX4sH9laLoPh1cDy7f8AtG6wfvTS525/3UH/AI9XKf5+lMTCiiigAooooAKKKKAC iiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKK KKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooo oAKKKKACiiigAooooAKKKKACiiigAooooAcjvHKjxM6SKcqykhgexBHStD+29e7atqf/AIEyf41D pQB1a2BGRuPX6GvV/DHh+C/26ldzRPZW8pFxbA/vCoGQQPTJFcOJqqNRQcE/U9fAZdGvQlWlPlSd rWvfT1R5d/bevH/mLap0z/x8yf41nEsXZmLFmOWJJJJPXJr1zxJodtpTJPBfQSCdyyWwHzxRnJXO fy+teVaiAmpXQAwBK2BTwtZSm4qCj6Cx+XRw9GFaM3JSdtVYijnniR0inmjRzl0jkZQ31AOD+NJD LLb5ME0sJI2kxSFMj0OK9G1n4fX7+Nozp2jgaMxtiArjaVMaF+Cc9d1Y+p+FITrGu3Ut9aaRo9tq UtrDJMGIZgxwigcnAHPpXbdHk2ZyO99mwvIUzkqXOCfUj196Xzpt+/z5d+Nu7zDnHpnrj2rqY/AF 39t1GGbUbOCGxtUvDdMT5ckLEgMMfQ8e1MbwLePqFnDbX9pNZXVs12l8MrEsS4DMQeRjI496LoLH MCRwqqJZFCncgDEbT6j0PuKc1zcFgzXNwzA5DNK2Qemc561uar4WXT9Ah1q21e01GzmnMCGBWBDA ZOQelbXhbwtZ6/4Ju7ucLB9l1HNzeAEvHbiNWIA7kk4HuaLgcZaywJcJ9rWeWzLZmhil2M4weQTk Z98Vd13W5NZ1cXiRfZIoYo4LWGJz+4jQAIoPHIx19a1G0208R3F/qdqLTQ9CsykXmTbmyTnaCByz nGTjpTovAt1NqZtU1Gza2bTn1KG+BPlSQqQCfYjnIPTFLQDlCAc553dc/wBakkmlnZDNNLLtGE8x y20egznFdE3gu5nu9Ii0y/tb+31UyiG5jBREMX+s3huRtHOe4pbnwlBHoz6va+ILG8so7qO1keNW XYz55IPYYznvTuFjm3dpGy7s7YxlmJPHTrTc1bfytM1Zgpt7+KCUgEg+VMAevY4NdlctY3vg22kf QNLs9Q1a8W2sXtkcFIwQHkOWPqAPrQ2BwVFeieLPDUukWN7a2Ghaa1rZBRNd+cXu19ZGUHCqTnt0 rzv/APVQmAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUU UUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRR QAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAWLGdba+hnkyVU5OPoR/Wu 20Tx3a6HNcTwQrJNNF5QeRD+7z3HrXAgZbHrXU+C/BM/jTULq0gvo7U28QlJdC2cnGOCKipgfbL2 zv7vU7sLmdXDU3Qgk1LWzX/BRqaz46g1yW2muQFlhgEJeOMjfgk7j+dcRdyi4u55lBAdywB967Hx F8Nrnw9qCWkupRTs0QkDLEQBkkY6+1cZcQtb3EsD4LRsVOO+Kwo0qUJtxd31OjHVsXVw9N1YKMOl v+HZv63r1rqfj1ddhSUWyvbNtYfP+7RFPH/ASfxrSvfE2ia7FqVjqq3sFrJqcuoWk9sqs6b8gqwP sf0rI1DwZr2l2Ml3e2SRQIgdiZ0LBTgg7Qc9x2rBrqPJudtd+M7C4tdZtYraeO3m0yLT7IHBbCMW 3P6ZyelWNF8UW8tlpekjT727iTTrizvUt0zJtdlIZB3xjn61wOaltrq4s5hPa3EkEq8CSNypH4il YLndeJ7Wx0r4b6bY20V5EZdReYC+QJK67cbtnYdqytC8Xv4e8NNaWQf7eNRF0MjMTx+WFZG9c4P5 1zlze3V/N513dTXEgGN8zliPbnpUFFgudrJr3hee11HSvs99a6VfSx3qeUql7W4VSrKAfvIR+WKQ eLdNgWWxtbe5XT4dBudLtTJgyPJK24u46AFiePSuPgt5ru4it7eJ5ZpmCJGgyzMewFaV54Y1nT72 0sp7Em6uztghikSRnb0+UnB+tFkM2/DPiKKzh0GwSwuLySCe+FzBEPmkiuEVSE9WAUmtK+sdI0f4 bXFukWqRQXerW+GvYhHLIqBidqf7IHU9Sa5HUdF1rw1NbzXUMlo7ljBPFKCMjqAyngj0681Su7+9 1CVZb67nuXUYUzSFtv0z0/8ArUWFcZeC3+1zixMhtt5EJlHz7e2fetvXvEEV5qOkTaajx22l20Mc CyDHzqdzH8Tj8q5+imB2994q0TdrepafBff2prUHkzxzbfKhzjcQRy2ccVxFFFCVgCiiigAooooA KKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAo oooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACii igAooooAKKKKACiiigAooooAKKKKACiiigByffFes/Av/kY9W/681/8AQ68kHHTtWxoHijV/DN1N c6TcrBLMnluxQNlQcjrXZDERjhp0Xu/+AZ8r51I9i+Jn/Iywf9ei/wDoTV4hqx/4mt5/11Y1q6p4 31/WbpLm+vFkmVAgIjAwMk/1NYMjtK7O5LMx3E+vrXmU6UozlJ9T2sXmFKtg6WHineO/b5Hf+Po9 AfxlMP8AiYnVm+xBwSn2cgxRdsbvu+/WrmpWlrJ47120s9H0Sz0zRQ0kkk9tuVAVHzMo5fk8A8D1 rzy81K91DUDfXVxJLdErmRuvygBfyAH5Vag8Sazb6xPq0GoTJf3BPnTA8yZwDn8hW1jyrnpB0XQo 9Wtb7+zrO5hn0Ge6eIW/kxSSIQA4TnbnPrVDRtG0nxTZeHtSudMtbWSWW4Wa3s08tLny1JVcDvx+ Iri5/FWvXM3nT6nPJIIWtwxPSNuWX6GqcWrahBa2tvDeSxxWkpmgVDjy3PVhiiwXOw8LNp/izXpR f6NptnFYWstwsMFsVV2UgBXA5bbnke1Ra5d6FBa6ffafbaZf3zpNFcLbWbR27KfuyBefmX1FYNz4 u8QXd7b3s2rXDXNsSYpAcFc9enrSXHizXrm9W7m1OZp1iaENxwjfeH40WC5rfDX7OPFFzLOryNDp d1JEsZw7OFA+U/3tpbGOlbfhWwsLnUfDniTRrWTTXN3drPbO73AmSKEu7R7jksysy8Hhue1ed2l3 cWF3FdWkzwXELbo5IzhlPsav3nibWr/UrbULjU7h7u1P7iUNgxf7vp/WhoLm9rEmnXvw2tJ9Dt7m 00231iRZYLt/Md5ZIshlf0Crgr6nNcZWnq/iHV9d8oarfzXKwklFc8KT1OPU+tZlNKwmwooooAKK KKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooo oAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiig AooooAKKKKACiiigAooooAKKKKACiiigAooooAKKKKACiiigBr5CHHBrdvrfwymi6M+m3lxNqsjY vYZB8i89qy7J0ivYWfhQeSe3FdB9utf+fiL/AL6FEsxeGXIqblfW9/lbZnvZPlNHGRdWpWUHF7O2 uz7r0FFnbf8APvH/AN8CuflWGPUmDozQrL8yI20lc8gHnB963vt9qOftEf8A31XPXLrJdzMpBVnJ BFeXl/tOeXPf5ns8VvCuhT9g43v0t28js7nRvDL+H9Iu9O0bWHvNWlngt4m1JMRvHtwSTGAQS3t0 61l23hTVbTVtLS90mO/hvJTHFHBfRmOdgOU81GIVu/XNaWm6n4an0rwnYazKslvaXN215CFY7N+z yy4XkrkHIHNb9t4n0K0i8ORS6npLSWesG5uP7MsnggjiMbAEDYC3JGTjNenqj4k4X/hFdZn1OztI NP8A3uo72tIxKrblViCN2eMdOait/DOsXMSPDZ5D3LWo3yon7xclgSxGAMHJPHFdZpfjGw0/w5ez ecTrNldTjTE2nLxTOCxBxxjAPUVa1PXvCGoeItPgeWKXSY4JrnM0UjQreykH94oG4qDuz9aLsLI5 D/hDfEB1K1sEsEmnukaS2MFzHJHKq/e2uGKkj0zmkm8H69by2aS2kQ+2SGGF1uonTzB1VmDEKR3B IruoPFOg2zeH1fVNNZ7OO7E7WNm0EKM6ttCrtHGSOcc9a4+wudNuPA/9iXOow2k02seezSROwSMx qN5AHTI7UXYWMnSNN+3+JdP0mbK/aL2K2k2MMgM4VsHkdzV/xVZ6Xpd21naaPq2nyxSNmTUJiwmj U4DKpRcdOvP9ayLaKL+0IoftyW8Qk2i8w21B2fA+bHTpzXZjxHY6NpFhZ3N/F4suINTW+RGeXyYE VCoXfIoYlmIYqBt+TnrihgjO1XwpDo/gSz1W4eVdXlvkintiflgieFpEVh/fKqrHngOARmuVruNW 8UaFqnge+txpjwapdasLoq97JM2TGwMxJUA9du3/AGs9q4f/APXQhMKKKKYBRRRQAUUUUAFFFFAB RRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFF FFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUU UAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAHrWhFot9PCsyouxhkEsBxWcfun6V658PbfSbjUNPXU ppEkzF9njEe5ZTg5D+3T86wr1ZQty9T0suwtKvzyq3tFX0PM59HvbeBpnRdijJIYHFUP1r1Px/Bp cE2pLpk8j587z1ePYI2z0X1FeWA4wSAQDkg96MPUlNPm6CzLC0sPKHsr2kr67/kWPsF79l+1fZJ/ s4GfOMZ24+vSq/X8/WvSNX1B/FkN5q+ka3eCwhhRtR0B5WjEEKgB9ij5WQcnIGeaLr4f2Qh8RiBp fPVt+jKW/wBbGIxKc+vysB9a2uefY8+SyupLGW+W3ka0idUkmA+RWPQE+pqE+/X0NejXegaLplpq TRx3cyadf2UEsP2ohJXYKXJGMcFuOOMU7XodJ1P4oXmmReHXmkZ0Vit8Y1X5FJcgIdoC9v8AGi4W PN/w7cU2vSLTwv4d1S41nUdNtpJtNsZUtYLeS9EXnSEZZzIRwvoMHNJN4V8Oae3iC7lWa8tbG0tr iGCG6GUeQsGjZwDnGOtO4rHATWdzbw2880EkcVyheF2HEi5IJHryKg/yM16JPp8OsWXguBNOmntv 7OuJjbRzhNiiVsbpD0UZGTjPtUzeDNC/tvRmkWSPT77Try4nhtrsXHlvAG+5IAA3Tp68Urjsea/y qaO0uJbSe6ihd7e32+dIB8se44XJ9zxXZ6b4Z0fxTDoVzpsFzpqXWoyWF1HJN53ypEJt6nA525GP U1JbXehXXw88Uy6Vpt3aIslkHSW5EnmR+euDnA2t7cjnrTuFjgv88U8RSmFphE5iU7TIB8oJ7E9q vC0XWfEC2ui2siJdShLaCSQMy5wMFu/c16bq+jPpfw8v9Jj06d7TT7y3knmKY+0kMDKw/wBkYwPp 70m7CSPJ3tLmO3W4e2mSBjgSMhCn8elQ17AbiHWJvEdwviO1vNCm0tmg05ZcmDaq4/d/wFTnnvmv HlJwM9cZNNMGLRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFA BRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAF FFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAVtWWuXyJHBb25keMYB jDbh6dKz9NsJdU1O1sIjh7iQID6ep/AZNernSP8AhHGNjYq6RNgCQDmQ+uaxxPLGnzTjdFU8bVws v3UrNnm1/rl5LFLbz2/ltKPmLg7jnk9ayASjAjGVORmvdpPD8fiDSnt9VgiRGQeRIB+8jbGM5/Xm vDry1lsr24tJgBLBK0bgeqnBrWFJQgpRVkxSx1TFyvVd2jdu/Gl7c2V3bwadpVgb2MxXM1nblHlQ 9VyWOAe+KdH471qO90W6DQl9JiMUAKcMpwDvHfgAfhSL4PuH8DSeJhOMq+Ra4+Ywhghl+gZgPwNa Gh+C7TVU8OGW6nT+1TciTaB8nlBcYz65o0FqYLeIr9tP1G0JjK392t5M5HzCQNuGD6ZrYT4h6gl3 c3TaTpMlxdQCC4lMTBpVGByQ3cAVyMatIwCqWdjgBRkk+gHer82h6vbzQQ3GmXkMlw22ISQsu8+g p2C5pQ+Lprd7lIdI0pbG5VVmsTATC5Xo2M5De+agfxLdGHVIIrazgh1JI45Y4YtqosZJXaM8dTnN bC/D+9tr7WbG/WcT2Nl9otzEnE7ZAwB369u9cvcabqFpdJa3FhcxXMmNkLxMHbPTA7/hS0DU1rLx jqNkllGsNpJDa2clj5UyFklhdtzK4z6gHPtU0njjU3lsmS1sYEsrW4tIYoYiqLHMCGGM9QDxWNLo +pwXsdlNp13HdSAskLREM4AJJA78A9PSpI9B1iW4a3i0m9eZUDtGsLblU9CR2z/SiyHdkuneI9R0 qxsrWxdIvsd+b+KQDLeaUCHPtgdKu3fjO7udMvNNi03S7O0vJI5Z47aArvdHDAnJPcdPQmsGS1ni hhmlgkjhmLCJ2UgPtOGwe+DwfQ1vWehaMvhy01fWNamsvtk8sUEcVv5mfLC5JI/3hTEY17fy3mpz X4SO1klfcFtsosfAHy85HT1q4niXVU0K60g3UklvcyLI5klZnG3+EEnoe4qfwn4Yn8V66LCGYQwq N0tww4Reg49TwAPU1ZsfC1qbSe+1jVvsFmt61lA4iMjSyKSCcdgMc0g1K134qurjTJdPt7HT7GKc KLhrSEq8wHQMSTx6461hVoa3pM+haxc6bcMrvCRh16OpAIYfUGs+mAUUUUAFFFFABRRRQAUUUUAF FFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUU UUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRR QAUUUUAFFFFABRRRQAUUUUAafh3UF0rxHp9/J/q4ZgXPopBBP4Zr6EK297CjjbJEw3Rup/Ig180V u6N4w1rQovJsrr9x2ikUOo+gPSt6VVRTjJaHNXoudmtz2C21O7g1K4W9aNLWAM0zk/LGo6HP4dO9 eJajcHXPEd1cQgL9uu2Me44xubjJPTqPzqxqvijV9ZiMV3c/uS24xxgKrN6kDrWPWEXJR5XJvXqV Spcmr3PWhr/ha38VJoDQ3b28Vp/Yb3InX7OyEEM+3/fJOfYUeHTBpdx4Qsri7ty9lPqMUriVcDG0 A9ehxxXkvt2ox/LFKx0XOi8AXVpYeLrKa+dIo8OqSSfdjkIwrH6H+dbszanofg/U4PEGprNd3F1C 9mqXYmcMrZeQEE7Vx24+lcBSAAdhTaFc9d1C8uLTxL4r1IahH5N1pG+xkFyGz90HaM/Kc9qh8Max afZfCk2p3Uct2bS+gjknl+ZJC5Ee5uq/LkA9s15RgelBAP49aVh3PYbHUpLLxN4Ytrq2hsvs0t5M kkmo/anXMDjBYk4UsARk9+lYfgm6vtUsrm0v5ZH06e/WSW+TURBcWjhcb+SN6AHO3kZHSvOsD0FG AeoB+veiwXNPU7e6gtLN3vVubF5LgWREmSFWTDMU/g3HB9+tdj4Ik12O1sRNcab/AMIx5rtcx3Uk ZCoT8+VPzZOBjHpXnmBz79fekIBbJAPOeaYj1LwnrfhKK70zTLSW/tN2omeUkLsmwx8sOx5CquOP WqWo2Nt4n0E6bot1HvsdXnkcXcqRs0chOXBOAQDnp2rzukIHpSsO50fjnUbfU/F93PauJIUSOBZB 0fYoBI/HP5VztFFMQUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFAB RRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFF FFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUU UAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQ AUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFAB RRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFABRRRQAUUUUAFFFFAH/9k= )
While on August 24, 2019, security intelligence firm Bad Packets was able to discover 14,528 unpatched Pulse Secure servers, a subsequent scan as of last month yielded 2,099 vulnerable endpoints, indicating that a vast majority of organizations have patched their VPN gateways.
The fact that there are still over thousands of unpatched Pulse Secure VPN servers has made them a lucrative target for bad actors to distribute malware.
A report from ClearSky found Iranian state-sponsored hackers using CVE-2019-11510, among others, to penetrate and steal information from target IT and telecommunication companies across the world.
According to an NSA advisory from October 2019, the "exploit code is freely available online via the Metasploit framework, as well as GitHub. Malicious cyber actors are actively using this exploit code."
In a similar alert issued last year, the UK's National Cyber Security Centre (NCSC) warned that advanced threat groups are exploiting the vulnerability to target government, military, academic, business, and healthcare organizations.
More recently, Travelex, the foreign currency exchange and travel insurance firm, became a victim after cybercriminals planted Sodinokibi (REvil) ransomware on the company's networks via the Pulse Secure vulnerability. Although the ransomware operators demanded a ransom of $6 million (£4.6 million), a Wall Street Journal report last week said it paid $2.3 million in the form of 285 Bitcoin to resolve its problem.
In the face of ongoing attacks, it's recommended that organizations upgrade their Pulse Secure VPN, reset their credentials, and scan for unauthenticated log requests and exploit attempts.
CISA has also suggested removing any unapproved remote access programs and inspecting scheduled tasks for scripts or executables that may allow an attacker to connect to an environment.
For more steps to mitigate the flaw, head to NSA's advisory here.
The warning comes three months after another CISA alert urging users and administrators to patch Pulse Secure VPN environments to thwart attacks exploiting the vulnerability.
"Threat actors who successfully exploited CVE-2019-11510 and stole a victim organization's credentials will still be able to access — and move laterally through — that organization's network after the organization has patched this vulnerability if the organization did not change those stolen credentials," CISA said.
CISA has also released a tool to help network administrators look for any indicators of compromise associated with the flaw.
A Remote Code Execution Flaw
Tracked as CVE-2019-11510, the pre-authentication arbitrary file read vulnerability could allow remote unauthenticated attackers to compromise vulnerable VPN servers and gain access to all active users and their plain-text credentials, and execute arbitrary commands.
The flaw stems from the fact that directory traversal is hard-coded to be allowed if a path contains "dana/html5/acc," thus allowing an attacker to send specially crafted URLs to read sensitive files, such as "/etc/passwd" that contains information about each user on the system.
To address this issue, Pulse Secure released an out-of-band patch on April 24, 2019.
While on August 24, 2019, security intelligence firm Bad Packets was able to discover 14,528 unpatched Pulse Secure servers, a subsequent scan as of last month yielded 2,099 vulnerable endpoints, indicating that a vast majority of organizations have patched their VPN gateways.
Unpatched VPN Servers Become Lucrative Target
The fact that there are still over thousands of unpatched Pulse Secure VPN servers has made them a lucrative target for bad actors to distribute malware.
A report from ClearSky found Iranian state-sponsored hackers using CVE-2019-11510, among others, to penetrate and steal information from target IT and telecommunication companies across the world.
According to an NSA advisory from October 2019, the "exploit code is freely available online via the Metasploit framework, as well as GitHub. Malicious cyber actors are actively using this exploit code."
In a similar alert issued last year, the UK's National Cyber Security Centre (NCSC) warned that advanced threat groups are exploiting the vulnerability to target government, military, academic, business, and healthcare organizations.
More recently, Travelex, the foreign currency exchange and travel insurance firm, became a victim after cybercriminals planted Sodinokibi (REvil) ransomware on the company's networks via the Pulse Secure vulnerability. Although the ransomware operators demanded a ransom of $6 million (£4.6 million), a Wall Street Journal report last week said it paid $2.3 million in the form of 285 Bitcoin to resolve its problem.
In the face of ongoing attacks, it's recommended that organizations upgrade their Pulse Secure VPN, reset their credentials, and scan for unauthenticated log requests and exploit attempts.
CISA has also suggested removing any unapproved remote access programs and inspecting scheduled tasks for scripts or executables that may allow an attacker to connect to an environment.
For more steps to mitigate the flaw, head to NSA's advisory here.
Have something to say about this article? Comment below or share it with us on Facebook, Twitter or our LinkedIn Group.
Source: feedproxy.google.com
CISA Warns Patched Pulse Secure VPNs Could Still Expose Organizations To Hackers
Reviewed by Anonymous
on
4:30 AM
Rating:
![CISA Warns Patched Pulse Secure VPNs Could Still Expose Organizations To Hackers](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgz1zfHWk6FLg0EMxshpUiDYrkHjvrF2Xxma6cSY14kE9GjjxGT_7oQbftLh-lpwzKIyUIF2bIubXnzGn5hRD-k3ATSHFwGNHjTWJqiXidhJMnJCB_1Xzvj0aTwsxtcMqmxDzIayklO3ic/s72-c/h123.png)