Threat Advisory

Critical Vulnerabilities in Ewon Cosy+ Enable Root Access and Compromise Industrial Security

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Critical Infrastructure, Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Security researchers revealed severe vulnerabilities in the Ewon Cosy+, an industrial remote access gateway tool, which could lead to root access and device compromise. The flaws include OS command injection, insecure permissions, and a certificate request vulnerability. The command injection allows attackers to execute arbitrary commands via malicious OpenVPN configurations, while insecure permissions affect firmware versions prior to certain updates, and the certificate request vulnerability enables unauthorized certificate generation. With these vulnerabilities, attackers can gain root access, decrypt firmware, access sensitive data, and hijack VPN sessions. Organizations are advised to update their devices and strengthen security measures.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Security researchers revealed severe vulnerabilities in the Ewon Cosy+, an industrial remote access gateway tool, which could lead to root access and device compromise. The flaws include OS command injection, insecure permissions, and a certificate request vulnerability. The command injection allows attackers to execute arbitrary commands via malicious OpenVPN configurations, while insecure permissions affect firmware versions prior to certain updates, and the certificate request vulnerability enables unauthorized certificate generation. With these vulnerabilities, attackers can gain root access, decrypt firmware, access sensitive data, and hijack VPN sessions. Organizations are advised to update their devices and strengthen security measures.[emaillocker id="1283"]

  • CVE-2024-33896- OS Command Injection: Allows arbitrary command execution through a bypass in OpenVPN configurations, enabling attackers to gain root access and execute shell commands.
  • CVE-2024-33894- Insecure Permissions: Affects firmware versions 21.x below 21.2s10 and 22.x below 22.1s3, leading to potential unauthorized access and exploitation.
  • CVE-2024-33897- Certificate Request Vulnerability: Compromised devices can request certificates for unauthorized devices, leading to potential VPN session hijacking and unauthorized access.

The discovery of these critical vulnerabilities in Ewon Cosy+ highlights significant risks to industrial remote access systems, emphasizing the need for immediate firmware updates and enhanced security practices to protect sensitive industrial infrastructure from exploitation and unauthorized access.

RECOMMENDATION:

  • We strongly recommend that you update Ewon Cosy+ devices to versions 21.2s10 or later for 21.x firmware, and 22.1s3 or later for 22.x firmware.

REFERENCES:

The following reports contain further technical details:

https://cybersecuritynews.com/industrial-remote-access-gateway-tool-hacked/

[/emaillocker]
crossmenu