-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Advisory ID: SYSS-2024-060 Product: mbNET.mini Manufacturer: Red Lion Europe GmbH Affected Version(s): Firmware Versions: all current versions; other/similar devices are also affected (see manufacturer note[4]) Tested Version(s): Firmware Version: 2.2.13, 2.2.11 Vulnerability Type: Execution with Unnecessary Privileges (CWE-250) Risk Level: Low Solution Status: Open Manufacturer Notification: 2024-07-25 Solution Date: Not Fixed Public Disclosure: 2024-10-15 CVE Reference: Not yet assigned Author of Advisory: Moritz Abrell, SySS GmbH ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Overview: The mbNET.mini is a VPN gateway used for remote access and maintenance in industrial environments. The manufacturer describes the product as follows (see [1]): "The mbNET industrial router is the ideal basis for securely connecting your machines and systems to the Internet - for direct access or via our remote service portal (my)mbCONNECT24." ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Vulnerability Details: The mbNET.mini executes all tasks and services in the context of the user "root" and therefore with the highest system privileges. By compromising a single service, attackers automatically gain full system access. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Proof of Concept (PoC): Examining running processes: $ ps PID USER VSZ STAT COMMAND 1 root 2292 S init 2 root 0 SW [kthreadd] 3 root 0 SW [ksoftirqd/0] 4 root 0 SW [events/0] 5 root 0 SW [khelper] 8 root 0 SW [async/mgr] 59 root 0 DW [usb_wakeup thre] 160 root 0 SW [sync_supers] 162 root 0 SW [bdi-default] 164 root 0 SW [kblockd/0] 172 root 0 SW [otg_switch/0] 178 root 0 SW [khubd] 181 root 0 SW [kseriod] 199 root 0 SW [rpciod/0] 208 root 0 DW [usb_wakeup thre] 265 root 0 SW [kswapd0] 355 root 0 SW [aio/0] 374 root 0 SW [nfsiod] 392 root 0 SW [crypto/0] 1680 root 0 SW [mtdblock0] 1688 root 0 SW [mtdblock1] 1693 root 0 SW [mxs-spi.0] 1774 root 0 SW [wusbd] 1811 root 0 SW [usb_gadget_work] 1829 root 0 SW [kondemand/0] 1866 root 0 SW [pswitch] 2034 root 1780 S < udevd --daemon 2065 root 0 SWN [jffs2_gcd_mtd1] 3343 root 2292 S /sbin/syslogd -l 7 -s 200 -L -R 127.0.0.1 3345 root 2292 S /sbin/klogd 3346 root 1644 S /usr/bin/msg_disp 3368 root 9952 S /usr/bin/confnet 3566 root 2292 S /usr/sbin/httpd -h /www -p 80 3597 root 4900 S /usr/sbin/sshd 3664 root 2292 S {alarmd} /bin/sh /usr/bin/alarmd 3691 root 2292 S /usr/sbin/crond 3707 root 2292 S sh /usr/bin/internet.sh 3708 root 2292 S sh /usr/bin/connect_led.sh 3876 root 65032 S /opt/Eltima/eveusb/bin/eveusbd 3903 root 2292 S udhcpc -b -i eth1 -p /var/run/udhcpc-eth1.pid 4332 root 2292 S {miro2in} /bin/sh /usr/bin/miro2in 4370 root 2160 S cat /dev/ttyAM0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Solution: Not yet fixed. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Disclosure Timeline: 2024-07-23: Vulnerability discovered 2024-07-25: Vulnerability reported to manufacturer 2024-07-25: Manufacturer confirmed reception 2024-07-31: Manufacturer asked for alternative publication date 2024-07-31: Asked the manufacturer for updates on the planned fixes 2024-08-02: Manufacturer responded that the vulnerability will not be fixed 2024-09-24: Committment of the publication date (2024-10-15) 2024-10-15: Public disclosure ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ References: [1] mbNET product website https://mbconnectline.com/mbnet-en/ [2] SySS Security Advisory SYSS-2024-060 https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-060.txt [3] SySS Responsible Disclosure Policy https://www.syss.de/en/responsible-disclosure-policy [4] Manufacturer note https://advisories.mbconnectline.com/pdf/SIM2024-04.pdf ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Credits: This security vulnerability was found by Moritz Abrell of SySS GmbH. E-Mail: moritz.abrell@syss.de Public Key: https://www.syss.de/fileadmin/dokumente/PGPKeys/Moritz_Abrell.asc Key Fingerprint: 2927 7EB6 1A20 0679 79E9 87E6 AE0C 9BF8 F134 8B53 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Disclaimer: The information provided in this security advisory is provided "as is" and without warranty of any kind. Details of this security advisory may be updated in order to provide as accurate information as possible. The latest version of this security advisory is available on the SySS website. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Copyright: Creative Commons - Attribution (by) - Version 3.0 URL: http://creativecommons.org/licenses/by/3.0/deed.en -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKSd+thogBnl56Yfmrgyb+PE0i1MFAmcGHSQACgkQrgyb+PE0 i1OhWg/9F+NfjXVekOEiReC9qOnNw9AZSNWB44N9RntTlJOU92R10+R3Pj7tXBPr 4oJHx1vg6iwezrFe7vpJRk06mr18Ce4P0ElBMFYQctx1O0pCaJMgtdTwO9Xgx/H6 owQVR46ewtcfI/P0F1XC69ytY8TiAm7x5ZcU3z1XAvKjeAoMcx37dH4ByBCVazg3 LBJ4/2fCm4iEv8gLGdia2g43RuWXoKGoSUBp75FQCyrLanKomgw6JIa/n5f4OtNl oDtX9CDtNni4snSGQtnCNvzA8gKcs7L+n23jDy+vtfS6JbQumnPkK7QPY5+OGktK G6b92a9bIN38aW403CYHxsE82+CJSMFLNgepK9wmA5IV6Gdeqdz5/oDxIg285lWb 8fFGGeoQu+dC+CrtyC0VBk6On0ud27aISwiSRwi2KMgXesRMaH3ewYl9JBhaFe8u U1VZaWQmTtB5oAX8aQLZU4U3MWB61786bpVHAaSSv6Tx6Kjw6SvCwK4DvgSphgAZ LpIjW1JXdpa1YJpqGoLQW51dtxC2PRej1aBcf1Au/s3GUxKEF2mVbdXLiZFrqZTY OL1Th9w47jaaUfkxraK4ZZN7/1Cqwmqwgi94By6v/80obBu+F2SSjxbA8k53D7go 4FaBJuaZjYvmeWzSGhHjm0N7+AURjwRvUZyrI/iON3/Tr7x66l8= =vvjC -----END PGP SIGNATURE-----