{"id":58980,"date":"2024-08-19T19:29:53","date_gmt":"2024-08-19T16:29:53","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/180236\/SYSS-2024-033.txt"},"modified":"2024-08-19T19:29:53","modified_gmt":"2024-08-19T16:29:53","slug":"ewon-cosy-excessive-access","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/ewon-cosy-excessive-access\/","title":{"rendered":"Ewon Cosy+ Excessive Access"},"content":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>Hash: SHA512<\/p>\n<p>Advisory ID: SYSS-2024-033<br \/>Product: Ewon Cosy+<br \/>Manufacturer: HMS Industrial Networks AB<br \/>Affected Version(s): Firmware Versions: all versions<br \/>Tested Version(s): Firmware Version: 21.2s7<br \/>Vulnerability Type: Execution with Unnecessary Privileges (CWE-250)<br \/>Risk Level: Low<br \/>Solution Status: Open<br \/>Manufacturer Notification: 2024-04-10<br \/>Solution Date: Not yet fixed<br \/>Public Disclosure: 2024-08-11<br \/>CVE Reference: CVE-2024-33894<br \/>Author of Advisory: Moritz Abrell, SySS GmbH<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Overview:<\/p>\n<p>The Ewon Cosy+ is a VPN gateway used for remote access and maintenance<br \/>in industrial environments.<\/p>\n<p>The manufacturer describes the product as follows (see [1]):<\/p>\n<p>&#8220;The Ewon Cosy+ gateway establishes a secure VPN connection between<br \/>the machine (PLC, HMI, or other devices) and the remote engineer.<br \/>The connection happens through Talk2m, a highly secured industrial<br \/>cloud service. The Ewon Cosy+ makes industrial remote access easy<br \/>and secure like never before!&#8221;<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Vulnerability Details:<\/p>\n<p>The Ewon Cosy+ executes all tasks and services in the context<br \/>of the user &#8220;root&#8221; and therefore with the highest system privileges.<\/p>\n<p>By compromising a single service, attackers automatically gain full<br \/>system access.<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Proof of Concept (PoC):<\/p>\n<p>Examining running processes:<br \/>$&gt; ps<br \/>PID USER VSZ STAT COMMAND<br \/>1 root 6248 S {systemd} \/sbin\/init<br \/>2 root 0 SW [kthreadd]3 root 0 IW [kworker\/0:0]5 root 0 IW [kworker\/u2:0]6 root 0 IW&lt; [mm_percpu_wq]7 root 0 SW [ksoftirqd\/0]8 root 0 RW [rcu_sched]9 root 0 IW [rcu_bh]205 root 3044 S udevd &#8211;daemon<br \/>491 root 23344 S \/usr\/lib\/systemd\/systemd-journald<br \/>505 root 3524 S \/usr\/lib\/systemd\/systemd-udevd<br \/>530 root 0 IW [kworker\/u2:2]536 root 11908 S \/usr\/sbin\/rngd -f -r \/dev\/hwrng<br \/>537 root 50364 S \/usr\/sbin\/ModemManager &#8211;log-journal<br \/>538 root 2232 S \/usr\/sbin\/klogd -n<br \/>539 root 2232 S \/usr\/sbin\/syslogd -n<br \/>542 root 3556 S \/sbin\/agetty -o -p &#8212; \\u &#8211;noclear tty1 linux<br \/>547 root 22972 S \/usr\/root\/ewon\/bin\/modem-manager-handler<br \/>549 root 29860 R \/usr\/root\/ewon\/bin\/sysDSupervisor<br \/>555 root 21868 S \/usr\/root\/ewon\/bin\/sysUpdateManager<br \/>565 root 4760 S \/usr\/lib\/systemd\/systemd-logind<br \/>623 root 52596 S \/usr\/root\/ewon\/bin\/ewon<br \/>742 root 14064 S eveusbd -p<br \/>746 root 11696 S \/usr\/sbin\/chronyd -4 -n<br \/>790 root 2232 S udhcpc &#8211;script=\/usr\/root\/ewon\/bin\/bootpdhcp\/dhcpc.s<br \/>853 root 0 IW&lt; [kworker\/u3:3]926 root 0 RW [kworker\/0:2]1209 root 0 IW&lt; [kworker\/0:0H]1274 root 0 IW&lt; [kworker\/0:2H]1308 root 5004 S openvpn &#8211;auth-nocache &#8211;config \/var\/run\/openvpn.con<br \/>1315 root 2496 S sh<\/p>\n[&#8230;]\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Solution:<\/p>\n<p>According to the manufacturer, no fix is planned for the current device<br \/>generation and it is on the roadmap for future generations.[7]\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Disclosure Timeline:<\/p>\n<p>2024-04-04: Vulnerability discovered<br \/>2024-04-10: Vulnerability reported to manufacturer<br \/>2024-04-11: Manufacturer acknowlegded the vulnerabilities and asked for<br \/>a publication date for all findings<br \/>2024-04-12: Proposed dates for a discussion about publication<br \/>2024-04-19: Manufacturer sent a technical overview of the analysis;<br \/>a fix is planned for the next device generation<br \/>2024-04-30: CVE ID CVE-2024-33894[4] assigned by the manufacturer<br \/>2024-05-31: Manufacturer asked if the blog post[5] can be reviewed by HMS<br \/>2024-06-04: Proposed dates to review the blog post draft<br \/>2024-07-17: Blog post provided to HMS<br \/>2024-07-23: Inquiry about the status<br \/>2024-07-23: Manufacturer reviewed the blog post<br \/>2024-07-24: Manufacturer also asked for an appointment to discuss the blog<br \/>post<br \/>2024-07-29: Discussion with HMS about the blog post and final publication<br \/>actions<br \/>2024-08-11: Vulnerability disclosed at DEF CON[6]2024-08-11: Blog post published[5]\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>References:<\/p>\n[1] Ewon Cosy+ product website<br \/>https:\/\/www.hms-networks.com\/p\/ec71330-00ma-ewon-cosy-ethernet<br \/>[2] SySS Security Advisory SYSS-2024-033<br \/>https:\/\/www.syss.de\/fileadmin\/dokumente\/Publikationen\/Advisories\/SYSS-2024-033.txt<br \/>[3] SySS Responsible Disclosure Policy<br \/>https:\/\/www.syss.de\/en\/responsible-disclosure-policy<br \/>[4] CVE-2024-33894<br \/>https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-33894<br \/>[5] Blog post<br \/>https:\/\/blog.syss.com\/posts\/hacking-a-secure-industrial-remote-access-gateway\/<br \/>[6] DEF CON talk<br \/>https:\/\/defcon.org\/html\/defcon-32\/dc-32-speakers.html#54521<br \/>[7] Manufacturer note<br \/>https:\/\/hmsnetworks.blob.core.windows.net\/nlw\/docs\/default-source\/products\/cybersecurity\/security-advisory\/hms-security-advisory-2024-07-29-001&#8211;ewon-several-cosy&#8211;vulnerabilities.pdf<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Credits:<\/p>\n<p>This security vulnerability was found by Moritz Abrell of SySS GmbH.<\/p>\n<p>E-Mail:moritz.abrell@syss.de<br \/>Public Key:https:\/\/www.syss.de\/fileadmin\/dokumente\/PGPKeys\/Moritz_Abrell.asc<br \/>Key Fingerprint: 2927 7EB6 1A20 0679 79E9 87E6 AE0C 9BF8 F134 8B53<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Disclaimer:<\/p>\n<p>The information provided in this security advisory is provided &#8220;as is&#8221;<br \/>and without warranty of any kind. Details of this security advisory may<br \/>be updated in order to provide as accurate information as possible. The<br \/>latest version of this security advisory is available on the SySS website.<\/p>\n<p>~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~<\/p>\n<p>Copyright:<\/p>\n<p>Creative Commons &#8211; Attribution (by) &#8211; Version 3.0<br \/>URL:http:\/\/creativecommons.org\/licenses\/by\/3.0\/deed.en<br \/>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<\/p>\n<p>iQIzBAEBCgAdFiEEKSd+thogBnl56Yfmrgyb+PE0i1MFAmay45EACgkQrgyb+PE0<br \/>i1P5LRAAg9gPOXRL6URvnvUSI9Tsrqr\/sNXbEm6ZxnBjmOtrSACUqvL\/3G1mg31M<br \/>2zBXF\/P4HnLgZPywO+XTI0F9QmwIhvGvksh\/lvlMPt7sI9yk1Xt\/UauSWYEEAqbT<br \/>5wyq5i9K4ni9ehV0gnoBjwo+10wLpKOWn1sXBQkN93bGDexEJbxnxE\/0\/+3qjd1X<br \/>WkzoZ6MvggSFTNJcF0XkHxjuvjCc8HHmto9TV8YjrzbmMvqPFVcVc\/C8E5FkszFg<br \/>SRUEfDaQMZgEcvXOeLOp\/FkJwLIhp8yeGAseAy7ii5ZElmwELE7maE8\/sxeCym9e<br \/>f+ahwg0feHDFU1FYvY0s3sx6PJroy1K2wGS+JRXkHCC\/Rn+gBkdOK+09u+GCBq3K<br \/>+o8WYE92kLOjEYzdrkMh2\/XAXVqFaBA7EzX49KLZjlFhwPL\/AP2Se3Jne8G1HhNw<br \/>jxmLHu1O1yBX28x6Je2COd0iNxIVgtg6skqIePZajMq1Gw9BOrzqO12IT+fr0ecO<br \/>KlTs5zGsu1GhkmoGd2MZXuV0znty4UkTw1ozsNudwqftz6y3cwDmNKPSkSgmSr6a<br \/>Ygwb0w10XncZruqZhabKLR7byfeLDiyRykQuOe3cYHmHW7X3N9wSqfzp6Bpn7bcx<br \/>Qrr1dpzCn4LJRW14C3ZQD\/KEjPVIHgZ+ZIkNjHGreG+mHKygTWA=<br \/>=U9YV<br \/>&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;Hash: SHA512 Advisory ID: SYSS-2024-033Product: Ewon Cosy+Manufacturer: HMS Industrial Networks ABAffected Version(s): Firmware Versions: all versionsTested Version(s): Firmware Version: 21.2s7Vulnerability Type: Execution with Unnecessary Privileges (CWE-250)Risk Level: LowSolution Status: OpenManufacturer Notification: 2024-04-10Solution Date: Not yet fixedPublic Disclosure: 2024-08-11CVE Reference: CVE-2024-33894Author of Advisory: Moritz Abrell, SySS GmbH ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Overview: The Ewon Cosy+ is &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-58980","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58980","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=58980"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58980\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=58980"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=58980"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=58980"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}