EXECUTIVE SUMMARY:
Security researchers revealed severe vulnerabilities in the Ewon Cosy+, an industrial remote access gateway tool, which could lead to root access and device compromise. The flaws include OS command injection, insecure permissions, and a certificate request vulnerability. The command injection allows attackers to execute arbitrary commands via malicious OpenVPN configurations, while insecure permissions affect firmware versions prior to certain updates, and the certificate request vulnerability enables unauthorized certificate generation. With these vulnerabilities, attackers can gain root access, decrypt firmware, access sensitive data, and hijack VPN sessions. Organizations are advised to update their devices and strengthen security measures.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Security researchers revealed severe vulnerabilities in the Ewon Cosy+, an industrial remote access gateway tool, which could lead to root access and device compromise. The flaws include OS command injection, insecure permissions, and a certificate request vulnerability. The command injection allows attackers to execute arbitrary commands via malicious OpenVPN configurations, while insecure permissions affect firmware versions prior to certain updates, and the certificate request vulnerability enables unauthorized certificate generation. With these vulnerabilities, attackers can gain root access, decrypt firmware, access sensitive data, and hijack VPN sessions. Organizations are advised to update their devices and strengthen security measures.[emaillocker id="1283"]
The discovery of these critical vulnerabilities in Ewon Cosy+ highlights significant risks to industrial remote access systems, emphasizing the need for immediate firmware updates and enhanced security practices to protect sensitive industrial infrastructure from exploitation and unauthorized access.
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/industrial-remote-access-gateway-tool-hacked/
[/emaillocker]