If your organization uses managed file transfer (MFT) software, or if you are considering using an MFT product, you might have noticed a recent event that has given you cause for concern about managed file transfer security. As reported by SecurityWeek on February 3, noted independent cybersecurity researcher and reporter Brian Krebs of Krebs on Security posted a warning to infosec.exchange about a “zero-day remote code injection exploit” affecting a popular MFT software product. A “zero day” vulnerability is a weakness in a product or code that is previously unknown to the maker, thus leaving it open to attack by threat actors.
In response to the zero-day’s discovery the vendor temporarily shut down the MFT service to limit customer exposure and give its team time to fix the issue and issue a patch (distributed on February 7). It is not known yet whether the vulnerability was successfully exploited by malicious hackers, and the disclosure was only available to authenticated customers. Krebs created an account, obtained the customer advisory, and posted it to infosec.exchange.
You Have Questions, We Have Answers
As news of this situation spreads, several MFT cybersecurity questions will come to mind as users of any MFT product are naturally concerned about information security and rely on managed file transfer software to keep data safe during exchanges with partners, vendors, government agencies, and other organizations. As these questions about MFT cybersecurity arise, we want to make sure Coviant Software customers and the public are informed about the implications in a general sense. Here are some common and frequently asked questions related to this incident affecting managed file transfer security that users of other products might have:
I use a different MFT product. Am I vulnerable to this zero-day exploit?
Each software vendor creates their own software in their own way. A vulnerability in one solution does not mean that it exists in all solutions. For example, when the Log4j vulnerability was disclosed, it was severe as the utility was widely used in many—but not all—software products. Our Diplomat MFT family of managed file transfer platforms, for example, was unaffected because we don’t use Log4j, while other software might.
If there are any questions about whether this exploit affects the security of the managed file transfer product you use, you should contact your vendor immediately.
Is Coviant Software’s Diplomat MFT platform safe from this zero-day exploit?
Yes. The vulnerability present in the product in question does not exist with Diplomat MFT. The weakness at issue was related to an option for accessing an administration console in the cloud, and due to bug(s) in the code that implemented an administrative function specific to that product. Because Diplomat MFT is different software that does not have this vulnerable code path, it is not susceptible to this zero-day exploit.
I use a different MFT product. Could a similar vulnerability put my MFT software at risk?
Most software products are complex, and every software product is likely to have some bugs. Some bugs may affect performance, while others may affect security. One strategy software developers use to mitigate the risk of bugs causing severe problems is to lock down code execution paths, making them available only for appropriate access. For example, if you have internet-accessible endpoints, they may be susceptible to exploitation if a bug exists. To minimize risk, developers may choose to limit access only to authenticated users with an affirmed need. For example, restricting administration and monitoring functions to the corporate network, not the Internet.
My organization uses a solution that was developed in-house. Are we safe?
When information security and data privacy are involved, organizations should only purchase software from reputable vendors who employ good security practices when they develop software. That includes full documentation of every update, conducting regular testing, patching, and security audits, and providing excellent technical and customer support.
I was looking at different MFT options and now I’m concerned about security. What should I do?
Don’t abandon the search. Secure managed file transfer software is still a vital part of any comprehensive data security program. MFT software that automatically encrypts files, uses secure communications protocols, documents processes for auditability, and confirms transfer success and alerts of any trouble is important for sharing vital files throughout the digital supply chain. Financial data, medical data, intellectual property, and other sensitive information that your organization needs to protect should only be shared using a secure managed file transfer platform.
What can I do to ensure my managed file transfer is secure?
Conduct informed due diligence before making an investment in a managed file transfer product. Then, maintaining proper configuration is very important. Understand the software and its security architecture and policies. Do not expose the administration portal to the internet; instead, restrict access to the admin functions of the software to only those secure, back-end networks and/or machines that need access. Use a VPN or Bastion Host to access those administrative tools from remote locations. Ensure your administrative interface is only accessible behind your firewall via your back-end network, and that it is available only to those endpoints that should have access. Use edge gateways into the internet-facing DMZ. Never forsake security in favor of convenience.
What is the difference between Diplomat MFT and other managed file transfer products?
We believe in keeping things simple. After twenty years of providing an excellent managed file transfer platform we’ve learned some things, and that experience means we engineer our award-winning Diplomat MFT to do the task of transferring files simply, securely, and reliably. There are no unnecessary features or endless options–software bloat–increasing product complexity and the risk of failure. A managed file transfer platform should be easy to use, robust, and prioritize cybersecurity.
Using this experience to inform your evaluation of secure MFT products can help you to make a better decision. Of course, we’d be honored if our award-winning Diplomat MFT software were included in your search. We are confident that Diplomat MFT is engineered to be secure and perform as needed at whatever scale or volume you require. And our passion for customer and technical support is tops in the industry.
Coviant Software is also committed to transparent, ethical pricing. Diplomat MFT comes in three versions that are right-sized for the needs of every organization, and at a price that is not prohibitive. Contact us to schedule a demonstration.
