工控系統遠端存取解決方案Ewon Cosy+存在漏洞,攻擊者有機會取得root權限
支付動態 · 2024-08-13

研究人員在上週末舉辦的資安會議DEF CON 32,揭露工業級遠端存取解決方案Ewon Cosy+的漏洞,並指出將會造成相當嚴重的危害,呼籲IT人員應儘速套用新版韌體因應

針對這套遠端存取系統的架構,研究人員提出說明。Ewon Cosy+透過OpenVPN對廠商管理的平臺Talk2m進行路由,從而建立VPN連線,操作員藉此遠端存取工業控制閘道。

研究人員發現,攻擊者可在上傳特製的OpenVPN組態的過程中,輸入額外的符號繞過過濾器的防護,觸發作業系統命令注入漏洞,甚至能藉由特定的OpenVPN組態產生反向Shell。

由於OpenVPN執行使用root的權限,研究人員藉由上述管道也試圖對Ewon Cosy+進行root提權,後續他們也挖掘出跨網站指令碼(XSS)漏洞,未經身分驗證的攻擊者,能藉此利用事件記錄讓FTP服務中毒並觸發漏洞。

接著,攻擊者有機會進一步擴大攻擊鏈,以便維持在受害設備運作,或是存取韌體特定的加密金鑰,或是解開韌體的更新檔案。再者,研究人員也發現寫死在可執行檔的金鑰,攻擊者可用來破解帳密資訊。

另一方面,Cosy+與Talk2m的API通訊透過HTTPS進行,並透過雙向驗證TLS(mutual TLS,mTLS)機制保護,若是企業將Cosy+裝置指派給Talk2m帳號,將會產生憑證簽章請求(Certificate Signing Request,CSR)。但研究人員發現,攻擊者有機會濫用裝置的序號註冊CSR,而有可能覆蓋原本的VPN通訊,並對用戶端發動攻擊。

Popular articles
Across 6 Cities: HUIDU Invites You to 8 World Cup Parties Redefining High-Value Social Networking
HUIDU Focus
PropellerAds Shared a New iGaming Case Study: 97,674 Installs and 12,701 Deposits in 3 Months
Marketing
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
GAT CDMX 2025 Institutional Academy: Leaders and Experts Analyze the Present and Future of the Gaming Industry in Mexico and Lat
Sports Game
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
SBC Summit Canada to Make Player Safety a Key Pillar of 2026 Agenda
Marketing
HUIDU Invites You to Booth T70 at iGB L!VE 2026 — Let’s Ignite London This July!
HUIDU Focus
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
Indiana online casino bill stalls in House committee
Regulation
Gaming & Technology Expo Makes a Powerful Entrance in CDMX
Marketing
Kazakhstan plans to penalise online casino promotions
Regulation
British gambling levy rates confirmed for each vertical
Regulation
Home
Game
Cooperation
Find
My